# Enriching Web Filter Logs with Username from Traffic Logs Using Session ID in Fortinet Logs

**URL:** <https://discuss.elastic.co/t/enriching-web-filter-logs-with-username-from-traffic-logs-using-session-id-in-fortinet-logs/377978>\
**Category:** SIEM\
**Created:** [May 9, 2025, 6:07am UTC](https://discuss.elastic.co/t/enriching-web-filter-logs-with-username-from-traffic-logs-using-session-id-in-fortinet-logs/377978 "2025-05-09T06:07:29Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Johan\_Alda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johan_alda/32/143017_2.png) [@Johan\_Alda](https://discuss.elastic.co/u/Johan_Alda)\
**Post date:** [May 9, 2025, 6:07am UTC](https://discuss.elastic.co/t/enriching-web-filter-logs-with-username-from-traffic-logs-using-session-id-in-fortinet-logs/377978/1 "2025-05-09T06:07:29Z")

</div>

### **Title:**

How to Enrich Fortinet UTM Web Filter Logs with Username from Traffic Logs Using Session ID?

### **Body:**

Hi everyone,

I'm working on a detection use case using Fortinet logs ingested into Elasticsearch.

### Objective:

I want to detect **Web Filter (UTM)** events (from `fortigate.utm` index) that match certain risk categories like:

- _Drug Abuse_
- _Hacking_
- _Illegal or Unethical_
- _Extremist Groups_
- _Child Sexual Abuse_, etc.

However, these UTM logs **do not contain user identity information** (like `source.user.name`), which only appears in **traffic logs** (`fortigate.traffic` index).

### What I’ve tried:

I'm using an EQL `sequence` rule in Elastic Security to correlate events based on the shared field `fortinet.firewall.sessionid` like this:

```auto
sequence by fortinet.firewall.sessionid with maxspan = 1h
  [web where fortinet.firewall.subtype == "webfilter"
        and not event.action in ("block", "blocked")
        and rule.category in (
            "Drug Abuse", "Hacking", "Discrimination or Unethical", 
            "Illegal or Unethical", "Extremist Groups", "Explicit Violence",
            "Proxy Avoidance", "Plagiarism", "Child Sexual Abuse", "Terrorism")]
  [network where fortinet.firewall.type == "traffic" and source.user.name != null]

```

The goal is to generate an alert when a web filtering event in these categories occurs **and** the correlated session in traffic logs contains a `username`.

### The Issue:

Even though the sequence detects both stages correctly, the **final alert only shows fields from the first stage (webfilter)** and does **not include the `source.user.name`** from the traffic log.

* * *

### My Questions:

1. Is there a way in Elastic Security to **include fields from the second stage of a sequence** (e.g., `source.user.name`) in the generated alert?
2. Is there a recommended way to **enrich UTM logs with traffic log fields like username** using `sessionid`?  
(e.g., transform pipelines, enrichment index, etc.)
3. Would this work better with a `join` rule instead of `sequence`?

Any advice or examples from similar use cases would be really helpful. Thanks in advance!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 6, 2025, 6:07am UTC](https://discuss.elastic.co/t/enriching-web-filter-logs-with-username-from-traffic-logs-using-session-id-in-fortinet-logs/377978/2 "2025-06-06T06:07:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
