Repository navigation
Fortinet Integration Error #3897
Description
Activity
Pinging @elastic/security-external-integrations (Team:Security-External Integrations)
- addedIntegration:Fortinet(Deprecated) Use one of the specific fortinet_X labels. [Integration not found in source](Deprecated) Use one of the specific fortinet_X labels. [Integration not found in source]bugSomething isn't working, use only for issuesSomething isn't working, use only for issues
on Jul 29, 2022 It looks like the pipeline is fighting with itself; if
fortinet.firewall.fromis non-null,email.from.addressis populated with the content offortinet.firewall.fromand then unconditionallyfortinet.firewall.fromis attempted to be renamed to that now-constructed field.- append: field: email.from.address value: "{{fortinet.firewall.from}}" if: "ctx?.fortinet?.firewall?.from != null" - rename: field: fortinet.firewall.from target_field: email.from.address ignore_missing: trueI suspect that the correct fix is to remove the
renameprocessor entirely sinceemail.from.addressis supposed to be an array and I would guess that thefromfield in the Fortinet log it a single value. It would be helpful if you could provide a redacted log line from your firewall (you should be able to get this from theevent.originalin the failing document.Also, please note that the Fortinet integration is now deprecated and the fix will be into the Fortinet Fortigate integration. This is a drop-in replacement for the firewall dataset in the Fortinet integration.
Hi @efd6,
Thank you for the information
Here the event original (I' had to obfuscate some data)
<190>date=2022-07-29 time=14:17:14 devname="FGT-Principal" devid="XXXXXXXX" eventtime=1659097034396946116 tz="+0200" logid="0814044032" type="utm" subtype="voip" eventtype="voip" level="information" vd="VDOMX" session_id=285812576 epoch=0 event_id=6939 srcip=10.1.1.2 src_port=57904 dstip=192.168.1.10 dst_port=5060 proto=6 src_int="Int1" dst_int="Int2" policy_id=314 profile="default" voip_proto="sip" kind="register" action="permit" status="succeeded" duration=0 dir="session_origin" call_id="9c7bef42-54490003-00000cd0-00004a9b@10.1.1.2" from="sip:4537@192.168.1.10" to="sip:4537@192.168.1.10"Reacted by Dan Kortschak
Hi,
I've found errors in the Fortinet integration when ingesting Fortigate logs of
type: utmandsubtype: voip.The error.message is
field [email.from.address] already existsError is raising in logs-fortinet.firewall-1.7.0-utm pipeline in this processor
(In my environment I temporary solved adding
"if": "ctx?.email?.from?.address == nullcondition to the processor)