Skip to content

[fortinet_fortigate] Fix grok pattern for plain-word login sources. - #19935

Merged
haetamoudi merged 2 commits into
mainfrom
fix/0-update-the-grok-pattern-in-the-73870592
Jul 2, 2026
Merged

haetamoudi merged 2 commits into
mainfrom
fix/0-update-the-grok-pattern-in-the-73870592

Conversation

@ie-ops

@ie-ops ie-ops commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

Executive summary

The fix addresses a missing case where login messages with plain word identifiers (like 'fgfm_fgc') were failing to parse. The grok pattern in the 'ssh login 3' processor has been updated to make the IP-in-parentheses part optional using (?:\(%{IP:source.ip}\))?, allowing it to match both traditional formats like 'ssh(172.16.200.254)' and plain word formats like 'fgfm_fgc'. A test case has been added to verify the fix works correctly, and all tests pass.

Proposed commit message

[fortinet_fortigate] Fix grok pattern for plain-word login sources.

Root cause

The grok pattern in the 'ssh login 3' processor (line 81 of login.yml) expects the source identifier to match either 'jsconsole' or 'WORD(IP)' format. FortiOS emits events with the source as 'fgfm_fgc' (FortiClient Flexible Communication), which is just a plain word without parentheses, causing the pattern to fail and log an error.

Approach

Update the grok pattern in the 'ssh login 3' processor to accept plain word identifiers (like 'fgfm_fgc') in addition to the existing 'jsconsole' literal and 'WORD(IP)' formats. Make the IP in parentheses optional to accommodate FortiOS variants where the source is specified without an IP.

Implementation

  1. Step 1: Modify the grok pattern in packages/fortinet_fortigate/data_stream/log/elasticsearch/ingest_pipeline/login.yml at line 81. Change the source-matching portion from '(?:jsconsole|%{WORD}(%{IP:source.ip}))' to '(?:jsconsole|%{WORD}(?:(%{IP:source.ip}))?)', making the IP in parentheses optional.
  2. Step 2: Add a test case to packages/fortinet_fortigate/data_stream/log/_dev/test/pipeline/test-fortinet-7-4.log with the sanitized event containing 'from fgfm_fgc' to ensure this variant is covered by pipeline tests.
  3. Step 3: Generate the expected output for the new test case by running the pipeline against the new event and validating that 'event.outcome' and 'user.name' are correctly extracted, with source.ip coming from the 'srcip' field if available.

Pipeline changes

  • Modify grok pattern in 'ssh login 3' processor (line 81) to make IP in parentheses optional: change '(?:jsconsole|%{WORD}(%{IP:source.ip}))' to '(?:jsconsole|%{WORD}(?:(%{IP:source.ip}))?)'. This allows matching plain word identifiers like 'fgfm_fgc' without an IP in parentheses, while preserving extraction of IPs in formats like 'ssh(172.16.200.254)'.

Field / mapping changes

—

Sanitized error message

Processor grok with tag ssh login 3 in pipeline logs-fortinet_fortigate.log-login failed with message: [on_failure_message]

Sanitized log (event_sanitized excerpt)

<190>date=2026-06-27 time=02:37:26 devname="example-device" devid="FG000000000001" eventtime=1782542246278949972 tz="-0400" logid="0100032001" type="event" subtype="system" level="information" vd="root" logdesc="Admin login successful" sn="1782542246" user="alice.johnson" ui="fgfm_fgc" method="fgfm_fgc" srcip=internal dstip=internal action="login" status="success" reason="none" profile="super_admin" msg="Administrator alice.johnson logged in successfully from fgfm_fgc"

Reviewer concerns

For plain word identifiers without parentheses, the source.ip field won't be captured from the message parsing itself—though the raw srcip field is still available. The pattern is now more permissive, but the preceding if condition should filter most false positives.

Self-review findings

—

Risk and classification

  • Plan risk level: low
  • Tags: pipeline, processors, ingest, test-fixture
  • Impact: medium

Links

  • Issue: (no issue number)
  • Issue title: fortinet_fortigate.log [MISSING_CASE]: Processor grok with tag ssh login 3 in pipeline logs-fortinet_fortigate.…
  • Pipeline case: b93a164fb897c665

@ie-ops ie-ops added enhancement New feature or request Integration:fortinet_fortigate Fortinet FortiGate Firewall Logs source:integration_sentinel The PR was created via the Integration Sentinel pipeline Team:Integration-Experience Security Integrations Integration Experience [elastic/integration-experience] labels Jul 2, 2026
@github-actions

github-actions Bot commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

✅ Elastic Docs Style Checker (Vale)

No issues found on modified lines!


The Vale linter checks documentation changes against the Elastic Docs style guide. To use Vale locally or report issues, refer to Elastic style guide for Vale.

@haetamoudi
haetamoudi marked this pull request as ready for review July 2, 2026 14:53
@haetamoudi
haetamoudi requested a review from a team as a code owner July 2, 2026 14:53
@infra-vault-gh-plugin-prod

Copy link
Copy Markdown

Pinging @elastic/integration-experience (Team:Integration-Experience)

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

✅ All changelog entries have the correct PR link.

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@infra-vault-gh-plugin-prod

Copy link
Copy Markdown

💚 Build Succeeded

@vera-review-bot

Copy link
Copy Markdown

No issues across the latest commits c6f2f8b.

I'll pick up this PR for review again after 15 minutes.

🤖 AI-Generated Review | Vera Review Bot | 📚 Knowledge base: integration-skills

⚠️ Automated review — verify suggestions before applying.

@mergify

mergify Bot commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

Tick the box to add this pull request to the merge queue (same as @mergifyio queue).

  • Queue this pull request

@haetamoudi
haetamoudi merged commit 22e0cba into elastic:main Jul 2, 2026
9 checks passed
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package fortinet_fortigate - 1.36.7 containing this change is available at https://epr.elastic.co/package/fortinet_fortigate/1.36.7/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request Integration:fortinet_fortigate Fortinet FortiGate Firewall Logs source:integration_sentinel The PR was created via the Integration Sentinel pipeline Team:Integration-Experience Security Integrations Integration Experience [elastic/integration-experience]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants