# Fortinet.tmp.\*

**URL:** <https://discuss.elastic.co/t/fortinet-tmp/267213>\
**Category:** SIEM\
**Created:** [March 15, 2021, 4:04am UTC](https://discuss.elastic.co/t/fortinet-tmp/267213 "2021-03-15T04:04:31Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![michaelv](https://avatars.discourse-cdn.com/v4/letter/m/90db22/32.png) [@michaelv](https://discuss.elastic.co/u/michaelv)\
**Post date:** [March 15, 2021, 4:04am UTC](https://discuss.elastic.co/t/fortinet-tmp/267213/1 "2021-03-15T04:04:32Z")

</div>

Hi,

I'm trying out fortinet filebeat plugin. Running ELK with 7.10.1 and filebeat 7.10.1  
However, I'm getting a strange input values into the documents (in the filebeat-\* index)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/0/e08eb374b6ba9e0f07cce7d952b4b40dbde6d244.png)

This is my config

```auto
- module: fortinet
  firewall:
    enabled: true

    # Set which input to use between tcp, udp (default) or file.
    var.input: udp

    # The interface to listen to syslog traffic. Defaults to
    # localhost. Set to 0.0.0.0 to bind to all available interfaces.
    var.syslog_host: 10.60.1.201

    # The port to listen for syslog traffic. Defaults to 9004.
    var.syslog_port: 9004
    input:
      processors:
        - add_fields:
            target: ''
            fields:
              fortinet.firewall.tz: '+800'

```

The question is why am I getting the "tmp" part of every data line?  
And how do I fix it?

I've verified that the pipelines exist  
GET /\_ingest/pipeline/filebeat-7.10.0-fortinet-firewall-pipeline

This is the pipeline that does the rename from fortinet.tmp to fortinet.firewall.  
But for some reason its not running.

Thanks in advance.

Regards,

Michael

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [March 15, 2021, 7:35pm UTC](https://discuss.elastic.co/t/fortinet-tmp/267213/2 "2021-03-15T19:35:14Z")

</div>

Moving this post to the SIEM category; that's where developers of the `fortinet` module hang out.

Shaunak

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [March 15, 2021, 11:49pm UTC](https://discuss.elastic.co/t/fortinet-tmp/267213/3 "2021-03-15T23:49:20Z")

</div>

I don't know much about this pipe and beats but does trying out the simulate API help out to see maybe why it's still adding it?

> **[Simulate pipeline API | Elasticsearch Reference \[master\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/master/simulate-pipeline-api.html#simulate-pipeline-api)**

See if that helps sleuth things out a bit?

---

<div class="post-metadata">

**Author:** ![michaelv](https://avatars.discourse-cdn.com/v4/letter/m/90db22/32.png) [@michaelv](https://discuss.elastic.co/u/michaelv)\
**Post date:** [March 16, 2021, 2:18am UTC](https://discuss.elastic.co/t/fortinet-tmp/267213/4 "2021-03-16T02:18:11Z")

</div>

> [@michaelv](#):
>
> /\_ingest/pipeline/filebeat-7.10.0-fortinet-firewall-pipeline

Thanks for moving it to SIEM category.

---

<div class="post-metadata">

**Author:** ![michaelv](https://avatars.discourse-cdn.com/v4/letter/m/90db22/32.png) [@michaelv](https://discuss.elastic.co/u/michaelv)\
**Post date:** [March 16, 2021, 2:20am UTC](https://discuss.elastic.co/t/fortinet-tmp/267213/5 "2021-03-16T02:20:59Z")

</div>

Did help a bit..

For some reason the message is a bit weird.  
When I ran

```auto
POST /_ingest/pipeline/filebeat-7.10.0-fortinet-firewall-pipeline/_simulate
{
  "docs": [
    {
      "_index": "filebeat-7.10.0-2021.03.08-000004",
      "_id": "id",
      "_source": {
        "event.module": "fortinet"
      }
    },
    {
      "_index": "filebeat-7.10.0-2021.03.08-000004",
      "_id": "id",
      "_source": {
        "event.module": "fortinet"
      }
    }
  ]
}

```

```auto
{
  "docs" : [
    {
      "doc" : {
        "_index" : "filebeat-7.10.0-2021.03.08-000004",
        "_type" : "_doc",
        "_id" : "id",
        "_source" : {
          "event.module" : "fortinet",
          "event" : {
            "ingested" : "2021-03-16T02:16:04.052466924Z"
          },
          "error" : {
            "message" : "field [message] not present as part of path [message]"
          }
        },
        "_ingest" : {
          "timestamp" : "2021-03-16T02:16:04.052466924Z"
        }
      }
    },
    {
      "doc" : {
        "_index" : "filebeat-7.10.0-2021.03.08-000004",
        "_type" : "_doc",
        "_id" : "id",
        "_source" : {
          "event.module" : "fortinet",
          "event" : {
            "ingested" : "2021-03-16T02:16:04.052482104Z"
          },
          "error" : {
            "message" : "field [message] not present as part of path [message]"
          }
        },
        "_ingest" : {
          "timestamp" : "2021-03-16T02:16:04.052482104Z"
        }
      }
    }
  ]
}

```

So for some reason my message field looks like this.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/3/73d2f431e144d6ca2fcbdc131ff3640c7ed77fe7.png)

Thanks for your help.  
Hopefully somebody from the SIEM category can offer some advise..

---

<div class="post-metadata">

**Author:** ![michaelv](https://avatars.discourse-cdn.com/v4/letter/m/90db22/32.png) [@michaelv](https://discuss.elastic.co/u/michaelv)\
**Post date:** [March 16, 2021, 2:26am UTC](https://discuss.elastic.co/t/fortinet-tmp/267213/6 "2021-03-16T02:26:33Z")

</div>

filebeat -e -d "\*"  
Gives this when the firewall packet comes it.

```auto
2021-03-16T10:24:30.180+0800 DEBUG [processors] processing/processors.go:203 Publish event: {
  "@timestamp": "2021-03-16T02:24:30.180Z",
  "@metadata": {
    "beat": "filebeat",
    "type": "_doc",
    "version": "7.10.1",
    "truncated": false,
    "pipeline": "filebeat-7.10.1-fortinet-firewall-pipeline"
  },
  "tags": [
    "fortinet-firewall",
    "forwarded"
  ],
  "fileset": {
    "name": "firewall"
  },
  "service": {
    "type": "fortinet"
  },
  "input": {
    "type": "udp"
  },
  "event": {
    "module": "fortinet",
    "dataset": "fortinet.firewall"
  },
  "agent": {
    "type": "filebeat",
    "version": "7.10.1",
    "hostname": "syslog-gather.test.com",
    "ephemeral_id": "a54da9e3-14eb-42b3-a5b0-cfab666709de",
    "id": "02e9efc7-3d89-479e-bdd7-29d626cccda3",
    "name": "syslog-gather.test.com"
  },
  "message": "<189>date=2021-03-16 time=10:24:30 devname=\"FGT60ETK18021220\" devid=\"FGT60ETK18021220\" logid=\"0001000014\" type=\"traffic\" subtype=\"local\" level=\"notice\" vd=\"root\" eventtime=1615861470 srcip=192.168.123.12 srcport=59594 srcintf=\"internal\" srcintfrole=\"lan\" dstip=192.168.123.255 dstport=10000 dstintf=unknown-0 dstintfrole=\"undefined\" sessionid=70500284 proto=17 action=\"deny\" policyid=0 policytype=\"local-in-policy\" service=\"udp/10000\" dstcountry=\"Reserved\" srccountry=\"Reserved\" trandisp=\"noop\" app=\"udp/10000\" duration=0 sentbyte=0 rcvdbyte=0 sentpkt=0 appcat=\"unscanned\"",
  "log": {
    "source": {
      "address": "192.168.123.137:4392"
    }
  },
  "ecs": {
    "version": "1.6.0"
  },
  "fortinet": {
    "firewall": {
      "tz": "+800"
    }
  }
}

```

The message field looks correct to me.

---

<div class="post-metadata">

**Author:** ![michaelv](https://avatars.discourse-cdn.com/v4/letter/m/90db22/32.png) [@michaelv](https://discuss.elastic.co/u/michaelv)\
**Post date:** [March 16, 2021, 3:48am UTC](https://discuss.elastic.co/t/fortinet-tmp/267213/7 "2021-03-16T03:48:48Z")

</div>

The pipelines has this:

```auto
        "kv" : {
          "ignore_failure" : false,
          "trim_value" : "\"",
          "field" : "syslog5424_sd",
          "field_split" : """ (?=[a-z\_\-]+=)""",
          "value_split" : "=",
          "prefix" : "fortinet.tmp.",
          "ignore_missing" : true
        }
      },
      {
        "remove" : {
          "if" : "ctx.fortinet?.tmp?.assignip == 'N/A'",
          "ignore_missing" : true,
          "field" : "fortinet.tmp.assignip"
        }
      },
      {
        "rename" : {
          "field" : "fortinet.tmp",
          "target_field" : "fortinet.firewall",
          "ignore_missing" : true
        }
      },

```

It does the KV part.. as I see the fields split into  
fortinet.tmp.  
But it skips the rename part where it renames fortinet.tmp to fortinet.firewall.

Please help.

Regards,

Michael

---

<div class="post-metadata">

**Author:** ![michaelv](https://avatars.discourse-cdn.com/v4/letter/m/90db22/32.png) [@michaelv](https://discuss.elastic.co/u/michaelv)\
**Post date:** [March 16, 2021, 5:45am UTC](https://discuss.elastic.co/t/fortinet-tmp/267213/8 "2021-03-16T05:45:41Z")

</div>

So I've found out that without the processor lines it works.. but with the processor lines it messes up.

```auto
    input:
      processors:
        - add_fields:
            target: ''
            fields:
              fortinet.firewall.tz: '+800'

```

---

<div class="post-metadata">

**Author:** ![michaelv](https://avatars.discourse-cdn.com/v4/letter/m/90db22/32.png) [@michaelv](https://discuss.elastic.co/u/michaelv)\
**Post date:** [March 17, 2021, 4:28am UTC](https://discuss.elastic.co/t/fortinet-tmp/267213/9 "2021-03-17T04:28:17Z")

</div>

Solution or not a solution..  
The problem with the solution of

```auto
    input:
      processors:
        - add_fields:
            target: ''
            fields:
              fortinet.firewall.tz: 'Asia/Singapore'

```

Does fix the timestamp correctly.. but when it hits this section of the pipeline

```auto
      {
        "rename" : {
          "target_field" : "fortinet.firewall",
          "ignore_missing" : true,
          "field" : "fortinet.tmp"
        }
      },

```

The rename fails because fortinet.firewall.tz already exist. This causes the rest of the pipeline to fail.  
To fix that you need to use a different field name as shown below.

The only way to get all of it to work is to add a new "set" in the pipeline and a custom settings in the config

So the pipeline filebeat-7.10.1-fortinet-firewall-pipeline add first set of fortinet.firewall.tz before the set for event.timezone.

```auto
      {
        "set" : {
          "field" : "fortinet.firewall.tz",
          "value" : "{{firewall.tz}}",
          "if" : "ctx.firewall.tz != null"
        }
      },
      {
        "set" : {
          "field" : "event.timezone",
          "value" : "{{fortinet.firewall.tz}}",
          "ignore_empty_value" : true
        }
      },

```

Then in the fortinet.yml add

```auto
    input:
      processors:
        - add_fields:
            target: ''
            fields:
              firewall.tz: "Asia/Singapore"

```

Hence, you need to add it for every version of filebeat pipeline for the firewall-pipeline  
Not ideal.. meaning you need to do for every filebeat version  
filebeat setup --pipeline module fortinet  
Then edit the pipeline as show and your fortinet.yml before actually ingesting data.

If you want you can also remove the added field by modifying the remove section

```auto
        "remove" : {
          "field" : [
            "_temp",
            "message",
            "syslog5424_sd",
            "syslog5424_pri",
            "fortinet.firewall.tz",
            "fortinet.firewall.date",
            "fortinet.firewall.eventtime",
            "fortinet.firewall.time",
            "fortinet.firewall.duration",
            "host",
            "firewall.tz"
          ],
          "ignore_missing" : true
        }
      },

```

Regards,

Michael

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 14, 2021, 6:28am UTC](https://discuss.elastic.co/t/fortinet-tmp/267213/10 "2021-04-14T06:28:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
