Repository navigation
[fortinet_fortigate] Copy xauthuser to source.user.name for vpn logs - #14921
Conversation
- Copy the xauthuser field to source.user.name, if it exists and the log subtype is vpn.
🚀 Benchmarks reportTo see the full report comment with |
| if: ctx.fortinet?.firewall?.subtype == 'vpn' && ctx.fortinet.firewall.xauthuser != null | ||
| - remove: | ||
| field: | ||
| - fortinet.firewall.advpnsc |
There was a problem hiding this comment.
is this intended?
Just checking since it seems unrelated and isn't mentioned in the PR description / changelog
There was a problem hiding this comment.
It showed up in an example log from the user. At first, I couldn't find documentation on it, so I dropped it (and we're also avoiding adding new vendor fields), but I just dug up the documentation for the field: https://docs.fortinet.com/document/fortigate/7.2.0/new-features/661245/add-log-field-to-identify-advpn-shortcuts-in-vpn-logs
Let me look at adding that field, maybe as a boolean type?
The advpnsc log field in VPN event logs indicates that a VPN event is based on an ADVPN shortcut. A value of 1 indicates the tunnel is an ADVPN shortcut, and 0 indicates it is not.
There was a problem hiding this comment.
Updated with mapping for advpnsc as a boolean. Also bumped the version up to a minor change/enhancement as a result.
There was a problem hiding this comment.
Sounds fair
I didn't realize it was "new" to us, I wanted to make sure we weren't deleting anything accidentally 😄
💚 Build Succeeded
History
|
|
|
Package fortinet_fortigate - 1.34.0 containing this change is available at https://epr.elastic.co/package/fortinet_fortigate/1.34.0/ |
…ng for advpnsc field for vpn logs (elastic#14921) - Copy the xauthuser field to source.user.name, if it exists and the log subtype is vpn. - Add mapping for advpnsc field
…ng for advpnsc field for vpn logs (elastic#14921) - Copy the xauthuser field to source.user.name, if it exists and the log subtype is vpn. - Add mapping for advpnsc field
Proposed commit message
Checklist
changelog.ymlfile.- [ ] I have verified that any added dashboard complies with Kibana's Dashboard good practicesHow to test this PR locally
Related issues