diff --git a/Sample Data/ASIM/Fortinet_Fortigate_WebSession_IngestedLogs.csv b/Sample Data/ASIM/Fortinet_Fortigate_WebSession_IngestedLogs.csv index 11accda0ff..0867c3f647 100644 --- a/Sample Data/ASIM/Fortinet_Fortigate_WebSession_IngestedLogs.csv +++ b/Sample Data/ASIM/Fortinet_Fortigate_WebSession_IngestedLogs.csv @@ -13,9 +13,9 @@ TenantId,"TimeGenerated [UTC]",DeviceVendor,DeviceProduct,DeviceVersion,DeviceEv "test-tenant-id","12/9/2024, 10:02:57.662 AM",Fortinet,"FortiGate-101E","7.0.14,build0601 (GA)",0317013312,"webfilter utm passthrough",5,"start=Dec 09 2024 11:02:56;logver=700140601;vd=root;eventtime=1733738576673815547;tz=""+0100"";logid=0317013312;subtype=webfilter;eventtype=ftgd_allow;deviceSeverity=notice;policyid=000;poluuid=00000000-0000-0000-0000-000000000000;policytype=policy;externalID=000000000;srccountry=Reserved;srcintfrole=lan;srcuuid=00000000-0000-0000-0000-000000000000;dstcountry=United States;dstintfrole=wan;dstuuid=00000000-0000-0000-0000-000000000000;profile=Webfilter;reqtype=direct;direction=outgoing;rawdata=Method=GET|User-Agent=Mozilla/5.0 (X11 Linux x86_64) AppleWebKit/537.36 (KHTML like Gecko) Chrome/60.0.3112.32 Safari/537.36",passthrough,HTTP,"test-fortigate-device","test-inbound-vlan","test-outbound-vlan","connectivitycheck.gstatic.com",80,"142.250.65.227","test-host","URL belongs to an allowed category in policy","192.168.1.2","test-host","http://connectivitycheck.gstatic.com/generate_204",CommonSecurityLog "test-tenant-id","12/9/2024, 9:54:58.821 AM",Fortinet,"FortiGate-101E","7.0.14,build0601 (GA)",0318012801,"webfilter utm passthrough",6,"start=Dec 09 2024 10:54:57;logver=700140601;vd=root;eventtime=1733738097548935397;tz=""+0100"";logid=0318012801;subtype=webfilter;eventtype=ftgd_err;deviceSeverity=warning;policyid=000;poluuid=00000000-0000-0000-0000-000000000000;policytype=policy;externalID=000000000;srccountry=Reserved;srcintfrole=lan;srcuuid=00000000-0000-0000-0000-000000000000;dstcountry=United States;dstintfrole=wan;dstuuid=00000000-0000-0000-0000-000000000000;profile=Webfilter;reqtype=direct;direction=outgoing;rawdata=Method=GET|User-Agent=Mozilla/5.0 (X11 Linux x86_64) AppleWebKit/537.36 (KHTML like Gecko) Chrome/60.0.3112.32 Safari/537.36",passthrough,HTTP,"test-fortigate-device","test-inbound-vlan","test-outbound-vlan","connectivitycheck.gstatic.com",80,"172.217.168.195","test-host","URL belongs to an allowed category in policy","192.168.1.2","test-host","http://connectivitycheck.gstatic.com/generate_204",CommonSecurityLog "test-tenant-id","12/9/2024, 10:02:20.139 AM",Fortinet,"FortiGate-101E","7.0.14,build0601 (GA)",0317013312,"webfilter utm passthrough",5,"start=Dec 09 2024 11:02:18;logver=700140601;vd=root;eventtime=1733738539033428721;tz=""+0100"";logid=0317013312;subtype=webfilter;eventtype=ftgd_allow;deviceSeverity=notice;policyid=000;poluuid=00000000-0000-0000-0000-000000000000;policytype=policy;externalID=000000000;srccountry=Reserved;srcintfrole=lan;srcuuid=00000000-0000-0000-0000-000000000000;dstcountry=United States;dstintfrole=wan;dstuuid=00000000-0000-0000-0000-000000000000;profile=Webfilter;reqtype=direct;direction=outgoing;rawdata=Method=HEAD|User-Agent=Mozilla/5.0 (X11 Linux aarch64) AppleWebKit/537.36 (KHTML like Gecko) Chrome/90.0.4430.225 Safari/537.36",passthrough,HTTP,"test-fortigate-device","test-inbound-vlan","test-outbound-vlan","connectivitycheck.gstatic.com",80,"142.250.187.195","test-host","URL belongs to an allowed category in policy","192.168.1.2","test-host","http://connectivitycheck.gstatic.com/generate_204",CommonSecurityLog -"test-tenant-id","12/9/2024, 10:02:01.276 AM",Fortinet,"FortiGate-101E","7.0.14,build0601 (GA)",0317013312,"webfilter utm passthrough",5,"start=Dec 09 2024 11:01:58;logver=700140601;vd=root;eventtime=1733738518753360834;tz=""+0100"";logid=0317013312;subtype=webfilter;eventtype=ftgd_allow;deviceSeverity=notice;policyid=000;poluuid=00000000-0000-0000-0000-000000000000;policytype=policy;externalID=000000000;srccountry=Reserved;srcintfrole=lan;srcuuid=00000000-0000-0000-0000-000000000000;dstcountry=United States;dstintfrole=wan;dstuuid=00000000-0000-0000-0000-000000000000;profile=Webfilter;reqtype=direct;direction=outgoing;rawdata=Method=GET|User-Agent=Mozilla/5.0 (X11 Linux x86_64) AppleWebKit/537.36 (KHTML like Gecko) Chrome/60.0.3112.32 Safari/537.36",passthrough,HTTP,"test-fortigate-device","test-inbound-vlan","test-outbound-vlan","gstatic.com",80,"172.217.17.67","test-host","192.168.2.10","test-host","URL belongs to an allowed category in policy","http://gstatic.com/",CommonSecurityLog -"test-tenant-id","12/9/2024, 10:02:58.897 AM",Fortinet,"FortiGate-101E","7.0.14,build0601 (GA)",0317013312,"webfilter utm passthrough",5,"start=Dec 09 2024 11:02:52;logver=700140601;vd=root;eventtime=1733738577040919079;tz=""+0100"";logid=0317013312;subtype=webfilter;eventtype=ftgd_allow;deviceSeverity=notice;policyid=000;poluuid=00000000-0000-0000-0000-000000000000;policytype=policy;externalID=000000000;srccountry=Reserved;srcintfrole=lan;srcuuid=00000000-0000-0000-0000-000000000000;dstcountry=United States;dstintfrole=wan;dstuuid=00000000-0000-0000-0000-000000000000;profile=Webfilter;reqtype=direct;direction=outgoing;rawdata=Method=GET|User-Agent=Mozilla/5.0 (X11 Linux x86_64) AppleWebKit/537.36 (KHTML like Gecko) Chrome/60.0.3112.32 Safari/537.36",passthrough,HTTP,"test-fortigate-device","test-inbound-vlan","test-outbound-vlan","connectivitycheck.gstatic.com",80,"142.250.187.195","test-host","192.168.1.2","test-host","URL belongs to an allowed category in policy","http://connectivitycheck.gstatic.com/generate_204",CommonSecurityLog -"test-tenant-id","12/9/2024, 10:02:59.044 AM",Fortinet,"FortiGate-101E","7.0.14,build0601 (GA)",0317013312,"webfilter utm passthrough",5,"start=Dec 09 2024 20:02:54;logver=700140601;vd=root;eventtime=1733738576522657421;tz=""+1000"";logid=0317013312;subtype=webfilter;eventtype=ftgd_allow;deviceSeverity=notice;policyid=000;poluuid=00000000-0000-0000-0000-000000000000;policytype=policy;externalID=000000000;srccountry=Reserved;srcintfrole=lan;srcuuid=00000000-0000-0000-0000-000000000000;dstcountry=United States;dstintfrole=wan;dstuuid=00000000-0000-0000-0000-000000000000;profile=Webfilter;reqtype=direct;direction=outgoing;rawdata=Method=GET|User-Agent=Mozilla/5.0 (X11 Linux x86_64) AppleWebKit/537.36 (KHTML like Gecko) Chrome/60.0.3112.32 Safari/537.36",passthrough,HTTP,"test-fortigate-device","test-inbound-vlan","test-outbound-vlan","connectivitycheck.gstatic.com",80,"142.250.66.195","test-host","192.168.1.2","test-host","URL belongs to an allowed category in policy","http://connectivitycheck.gstatic.com/generate_204",CommonSecurityLog -"test-tenant-id","12/9/2024, 10:02:52.496 AM",Fortinet,"FortiGate-101E","7.0.14,build0601 (GA)",0317013312,"webfilter utm passthrough",5,"start=Dec 09 2024 11:02:48;logver=700140601;vd=root;eventtime=1733738570438330090;tz=""+0100"";logid=0317013312;subtype=webfilter;eventtype=ftgd_allow;deviceSeverity=notice;policyid=000;poluuid=00000000-0000-0000-0000-000000000000;policytype=policy;externalID=000000000;srccountry=Reserved;srcintfrole=lan;srcuuid=00000000-0000-0000-0000-000000000000;dstcountry=United States;dstintfrole=wan;dstuuid=00000000-0000-0000-0000-000000000000;profile=Webfilter;reqtype=direct;direction=outgoing;rawdata=Method=GET|User-Agent=Mozilla/5.0 (X11 Linux x86_64) AppleWebKit/537.36 (KHTML like Gecko) Chrome/60.0.3112.32 Safari/537.36",passthrough,HTTP,"test-fortigate-device","test-inbound-vlan","test-outbound-vlan","apple.com",80,"184.28.84.242","test-host","192.168.50.2","test-host","URL belongs to an allowed category in policy","http://apple.com/",CommonSecurityLog -"test-tenant-id","12/9/2024, 9:57:56.865 AM",Fortinet,"FortiGate-101E","7.0.14,build0601 (GA)",0315012545,"webfilter utm passthrough",4,"start=Dec 09 2024 10:57:51;logver=700140601;vd=root;eventtime=1733738273866871021;tz=""+0100"";logid=0315012545;subtype=webfilter;eventtype=urlfilter;deviceSeverity=information;policyid=000;poluuid=00000000-0000-0000-0000-000000000000;policytype=policy;externalID=000000000;srccountry=Reserved;srcintfrole=lan;srcuuid=00000000-0000-0000-0000-000000000000;dstcountry=United States;dstintfrole=wan;dstuuid=00000000-0000-0000-0000-000000000000;profile=Webfilter;reqtype=direct;direction=outgoing;rawdata=Method=GET|User-Agent=Mozilla/5.0 (X11 Linux x86_64) AppleWebKit/537.36 (KHTML like Gecko) Chrome/60.0.3112.32 Safari/537.36",passthrough,HTTP,"test-fortigate-device","test-inbound-vlan","test-outbound-vlan","captive.apple.com",80,"184.28.84.242","test-host","192.168.7.2","test-host","URL belongs to an allowed category in policy","http://captive.apple.com/",CommonSecurityLog -"test-tenant-id","12/9/2024, 10:02:06.245 AM",Fortinet,"FortiGate-101E","7.0.14,build0601 (GA)",0317013312,"webfilter utm passthrough",5,"start=Dec 09 2024 11:02:04;logver=700150632;vd=root;eventtime=1733738525613152583;tz=""+0100"";logid=0317013312;subtype=webfilter;eventtype=ftgd_allow;deviceSeverity=notice;policyid=000;poluuid=00000000-0000-0000-0000-000000000000;policytype=policy;externalID=000000000;srccountry=Reserved;srcintfrole=lan;srcuuid=00000000-0000-0000-0000-000000000000;dstcountry=United States;dstintfrole=wan;dstuuid=00000000-0000-0000-0000-000000000000;profile=Webfilter;reqtype=direct;direction=outgoing;rawdata=Method=GET|User-Agent=Mozilla/5.0 (Windows NT 10.0 Win64 x64) AppleWebKit/537.36 (KHTML like Gecko) Chrome/132.0.0.0 Safari/537.36 Edg/132.0.0.0",passthrough,HTTP,"test-fortigate-device","test-inbound-vlan","test-outbound-vlan","edge-http.microsoft.com",80,"13.107.6.158","test-host","192.168.70.8","test-host","URL belongs to an allowed category in policy","http://edge-http.microsoft.com/captiveportal/generate_204",CommonSecurityLog +"test-tenant-id","12/9/2024, 10:02:01.276 AM",Fortinet,"FortiGate-101E","7.0.14,build0601 (GA)",0317013312,"webfilter utm passthrough",5,"start=Dec 09 2024 11:01:58;logver=700140601;vd=root;eventtime=1733738518753360834;tz=""+0100"";logid=0317013312;subtype=webfilter;eventtype=ftgd_allow;deviceSeverity=notice;policyid=000;poluuid=00000000-0000-0000-0000-000000000000;policytype=policy;externalID=000000000;srccountry=Reserved;srcintfrole=lan;srcuuid=00000000-0000-0000-0000-000000000000;dstcountry=United States;dstintfrole=wan;dstuuid=00000000-0000-0000-0000-000000000000;profile=Webfilter;reqtype=direct;direction=outgoing;rawdata=Method=GET|User-Agent=Mozilla/5.0 (X11 Linux x86_64) AppleWebKit/537.36 (KHTML like Gecko) Chrome/60.0.3112.32 Safari/537.36",passthrough,HTTP,"test-fortigate-device","test-inbound-vlan","test-outbound-vlan","gstatic.com",80,"172.217.17.67","test-host","URL belongs to an allowed category in policy","192.168.2.10","test-host","http://gstatic.com/",CommonSecurityLog +"test-tenant-id","12/9/2024, 10:02:58.897 AM",Fortinet,"FortiGate-101E","7.0.14,build0601 (GA)",0317013312,"webfilter utm passthrough",5,"start=Dec 09 2024 11:02:52;logver=700140601;vd=root;eventtime=1733738577040919079;tz=""+0100"";logid=0317013312;subtype=webfilter;eventtype=ftgd_allow;deviceSeverity=notice;policyid=000;poluuid=00000000-0000-0000-0000-000000000000;policytype=policy;externalID=000000000;srccountry=Reserved;srcintfrole=lan;srcuuid=00000000-0000-0000-0000-000000000000;dstcountry=United States;dstintfrole=wan;dstuuid=00000000-0000-0000-0000-000000000000;profile=Webfilter;reqtype=direct;direction=outgoing;rawdata=Method=GET|User-Agent=Mozilla/5.0 (X11 Linux x86_64) AppleWebKit/537.36 (KHTML like Gecko) Chrome/60.0.3112.32 Safari/537.36",passthrough,HTTP,"test-fortigate-device","test-inbound-vlan","test-outbound-vlan","connectivitycheck.gstatic.com",80,"142.250.187.195","test-host","URL belongs to an allowed category in policy","192.168.1.2","test-host","http://connectivitycheck.gstatic.com/generate_204",CommonSecurityLog +"test-tenant-id","12/9/2024, 10:02:59.044 AM",Fortinet,"FortiGate-101E","7.0.14,build0601 (GA)",0317013312,"webfilter utm passthrough",5,"start=Dec 09 2024 20:02:54;logver=700140601;vd=root;eventtime=1733738576522657421;tz=""+1000"";logid=0317013312;subtype=webfilter;eventtype=ftgd_allow;deviceSeverity=notice;policyid=000;poluuid=00000000-0000-0000-0000-000000000000;policytype=policy;externalID=000000000;srccountry=Reserved;srcintfrole=lan;srcuuid=00000000-0000-0000-0000-000000000000;dstcountry=United States;dstintfrole=wan;dstuuid=00000000-0000-0000-0000-000000000000;profile=Webfilter;reqtype=direct;direction=outgoing;rawdata=Method=GET|User-Agent=Mozilla/5.0 (X11 Linux x86_64) AppleWebKit/537.36 (KHTML like Gecko) Chrome/60.0.3112.32 Safari/537.36",passthrough,HTTP,"test-fortigate-device","test-inbound-vlan","test-outbound-vlan","connectivitycheck.gstatic.com",80,"142.250.66.195","test-host","URL belongs to an allowed category in policy","192.168.1.2","test-host","http://connectivitycheck.gstatic.com/generate_204",CommonSecurityLog +"test-tenant-id","12/9/2024, 10:02:52.496 AM",Fortinet,"FortiGate-101E","7.0.14,build0601 (GA)",0317013312,"webfilter utm passthrough",5,"start=Dec 09 2024 11:02:48;logver=700140601;vd=root;eventtime=1733738570438330090;tz=""+0100"";logid=0317013312;subtype=webfilter;eventtype=ftgd_allow;deviceSeverity=notice;policyid=000;poluuid=00000000-0000-0000-0000-000000000000;policytype=policy;externalID=000000000;srccountry=Reserved;srcintfrole=lan;srcuuid=00000000-0000-0000-0000-000000000000;dstcountry=United States;dstintfrole=wan;dstuuid=00000000-0000-0000-0000-000000000000;profile=Webfilter;reqtype=direct;direction=outgoing;rawdata=Method=GET|User-Agent=Mozilla/5.0 (X11 Linux x86_64) AppleWebKit/537.36 (KHTML like Gecko) Chrome/60.0.3112.32 Safari/537.36",passthrough,HTTP,"test-fortigate-device","test-inbound-vlan","test-outbound-vlan","apple.com",80,"184.28.84.242","test-host","URL belongs to an allowed category in policy","192.168.50.2","test-host","http://apple.com/",CommonSecurityLog +"test-tenant-id","12/9/2024, 9:57:56.865 AM",Fortinet,"FortiGate-101E","7.0.14,build0601 (GA)",0315012545,"webfilter utm passthrough",4,"start=Dec 09 2024 10:57:51;logver=700140601;vd=root;eventtime=1733738273866871021;tz=""+0100"";logid=0315012545;subtype=webfilter;eventtype=urlfilter;deviceSeverity=information;policyid=000;poluuid=00000000-0000-0000-0000-000000000000;policytype=policy;externalID=000000000;srccountry=Reserved;srcintfrole=lan;srcuuid=00000000-0000-0000-0000-000000000000;dstcountry=United States;dstintfrole=wan;dstuuid=00000000-0000-0000-0000-000000000000;profile=Webfilter;reqtype=direct;direction=outgoing;rawdata=Method=GET|User-Agent=Mozilla/5.0 (X11 Linux x86_64) AppleWebKit/537.36 (KHTML like Gecko) Chrome/60.0.3112.32 Safari/537.36",passthrough,HTTP,"test-fortigate-device","test-inbound-vlan","test-outbound-vlan","captive.apple.com",80,"184.28.84.242","test-host","URL belongs to an allowed category in policy","192.168.7.2","test-host","http://captive.apple.com/",CommonSecurityLog +"test-tenant-id","12/9/2024, 10:02:06.245 AM",Fortinet,"FortiGate-101E","7.0.14,build0601 (GA)",0317013312,"webfilter utm passthrough",5,"start=Dec 09 2024 11:02:04;logver=700150632;vd=root;eventtime=1733738525613152583;tz=""+0100"";logid=0317013312;subtype=webfilter;eventtype=ftgd_allow;deviceSeverity=notice;policyid=000;poluuid=00000000-0000-0000-0000-000000000000;policytype=policy;externalID=000000000;srccountry=Reserved;srcintfrole=lan;srcuuid=00000000-0000-0000-0000-000000000000;dstcountry=United States;dstintfrole=wan;dstuuid=00000000-0000-0000-0000-000000000000;profile=Webfilter;reqtype=direct;direction=outgoing;rawdata=Method=GET|User-Agent=Mozilla/5.0 (Windows NT 10.0 Win64 x64) AppleWebKit/537.36 (KHTML like Gecko) Chrome/132.0.0.0 Safari/537.36 Edg/132.0.0.0",passthrough,HTTP,"test-fortigate-device","test-inbound-vlan","test-outbound-vlan","edge-http.microsoft.com",80,"13.107.6.158","test-host","URL belongs to an allowed category in policy","192.168.70.8","test-host","http://edge-http.microsoft.com/captiveportal/generate_204",CommonSecurityLog