Repository navigation
[fortinet_fortigate] Fix grok pattern for plain-word login sources. - #19935
Conversation
✅ Elastic Docs Style Checker (Vale)No issues found on modified lines! The Vale linter checks documentation changes against the Elastic Docs style guide. To use Vale locally or report issues, refer to Elastic style guide for Vale. |
|
Pinging @elastic/integration-experience (Team:Integration-Experience) |
|
✅ All changelog entries have the correct PR link. |
🚀 Benchmarks reportTo see the full report comment with |
💚 Build Succeeded
|
|
No issues across the latest commits c6f2f8b.
🤖 AI-Generated Review | Vera Review Bot | 📚 Knowledge base: integration-skills
|
|
Tick the box to add this pull request to the merge queue (same as
|
|
Package fortinet_fortigate - 1.36.7 containing this change is available at https://epr.elastic.co/package/fortinet_fortigate/1.36.7/ |
Executive summary
The fix addresses a missing case where login messages with plain word identifiers (like 'fgfm_fgc') were failing to parse. The grok pattern in the 'ssh login 3' processor has been updated to make the IP-in-parentheses part optional using
(?:\(%{IP:source.ip}\))?, allowing it to match both traditional formats like 'ssh(172.16.200.254)' and plain word formats like 'fgfm_fgc'. A test case has been added to verify the fix works correctly, and all tests pass.Proposed commit message
Root cause
The grok pattern in the 'ssh login 3' processor (line 81 of login.yml) expects the source identifier to match either 'jsconsole' or 'WORD(IP)' format. FortiOS emits events with the source as 'fgfm_fgc' (FortiClient Flexible Communication), which is just a plain word without parentheses, causing the pattern to fail and log an error.
Approach
Update the grok pattern in the 'ssh login 3' processor to accept plain word identifiers (like 'fgfm_fgc') in addition to the existing 'jsconsole' literal and 'WORD(IP)' formats. Make the IP in parentheses optional to accommodate FortiOS variants where the source is specified without an IP.
Implementation
Pipeline changes
Field / mapping changes
—
Sanitized error message
Processor grok with tag ssh login 3 in pipeline logs-fortinet_fortigate.log-login failed with message: [on_failure_message]Sanitized log (
event_sanitizedexcerpt)<190>date=2026-06-27 time=02:37:26 devname="example-device" devid="FG000000000001" eventtime=1782542246278949972 tz="-0400" logid="0100032001" type="event" subtype="system" level="information" vd="root" logdesc="Admin login successful" sn="1782542246" user="alice.johnson" ui="fgfm_fgc" method="fgfm_fgc" srcip=internal dstip=internal action="login" status="success" reason="none" profile="super_admin" msg="Administrator alice.johnson logged in successfully from fgfm_fgc"Reviewer concerns
For plain word identifiers without parentheses, the source.ip field won't be captured from the message parsing itself—though the raw srcip field is still available. The pattern is now more permissive, but the preceding
ifcondition should filter most false positives.Self-review findings
—
Risk and classification
Links
b93a164fb897c665