Skip to content

[fortinet_fortigate] Copy xauthuser to source.user.name for vpn logs - #14921

Merged
taylor-swanson merged 6 commits into
elastic:mainfrom
taylor-swanson:bug/fortigate_vpn-username
Aug 14, 2025
Merged

taylor-swanson merged 6 commits into
elastic:mainfrom
taylor-swanson:bug/fortigate_vpn-username

Conversation

@taylor-swanson

@taylor-swanson taylor-swanson commented Aug 13, 2025 •

Copy link
Copy Markdown
Contributor

Proposed commit message

  • Copy the xauthuser field to source.user.name, if it exists and the log subtype is vpn.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
    - [ ] I have verified that any added dashboard complies with Kibana's Dashboard good practices

How to test this PR locally

cd packages/fortinet_fortigate
elastic-package test

Related issues

- Copy the xauthuser field to source.user.name, if it exists and the
log subtype is vpn.
@taylor-swanson taylor-swanson self-assigned this Aug 13, 2025
@taylor-swanson taylor-swanson added bugfix Pull request that fixes a bug issue Integration:fortinet_fortigate Fortinet FortiGate Firewall Logs Team:Integration-Experience Security Integrations Integration Experience [elastic/integration-experience] labels Aug 13, 2025
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@taylor-swanson
taylor-swanson marked this pull request as ready for review August 14, 2025 12:26
@taylor-swanson
taylor-swanson requested a review from a team as a code owner August 14, 2025 12:26

@kgeller kgeller left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One question, otherwise LGTM

if: ctx.fortinet?.firewall?.subtype == 'vpn' && ctx.fortinet.firewall.xauthuser != null
- remove:
field:
- fortinet.firewall.advpnsc

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

is this intended?

Just checking since it seems unrelated and isn't mentioned in the PR description / changelog

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It showed up in an example log from the user. At first, I couldn't find documentation on it, so I dropped it (and we're also avoiding adding new vendor fields), but I just dug up the documentation for the field: https://docs.fortinet.com/document/fortigate/7.2.0/new-features/661245/add-log-field-to-identify-advpn-shortcuts-in-vpn-logs

Let me look at adding that field, maybe as a boolean type?

The advpnsc log field in VPN event logs indicates that a VPN event is based on an ADVPN shortcut. A value of 1 indicates the tunnel is an ADVPN shortcut, and 0 indicates it is not.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Updated with mapping for advpnsc as a boolean. Also bumped the version up to a minor change/enhancement as a result.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sounds fair

I didn't realize it was "new" to us, I wanted to make sure we weren't deleting anything accidentally 😄

@elasticmachine

Copy link
Copy Markdown

💚 Build Succeeded

History

cc @taylor-swanson

@elastic-sonarqube

Copy link
Copy Markdown

@andrewkroh andrewkroh added the documentation Improvements or additions to documentation. Applied to PRs that modify *.md files. label Aug 14, 2025
@taylor-swanson
taylor-swanson merged commit bb73b42 into elastic:main Aug 14, 2025
@taylor-swanson
taylor-swanson deleted the bug/fortigate_vpn-username branch August 14, 2025 18:45
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package fortinet_fortigate - 1.34.0 containing this change is available at https://epr.elastic.co/package/fortinet_fortigate/1.34.0/

robester0403 pushed a commit to robester0403/integrations that referenced this pull request Aug 14, 2025
…ng for advpnsc field for vpn logs (elastic#14921)

- Copy the xauthuser field to source.user.name, if it exists and the
log subtype is vpn.
- Add mapping for advpnsc field
tehbooom pushed a commit to tehbooom/integrations that referenced this pull request Nov 19, 2025
…ng for advpnsc field for vpn logs (elastic#14921)

- Copy the xauthuser field to source.user.name, if it exists and the
log subtype is vpn.
- Add mapping for advpnsc field
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugfix Pull request that fixes a bug issue documentation Improvements or additions to documentation. Applied to PRs that modify *.md files. Integration:fortinet_fortigate Fortinet FortiGate Firewall Logs Team:Integration-Experience Security Integrations Integration Experience [elastic/integration-experience]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Fortinet Fortigate]: Wrong value in username field for VPN logs

4 participants