Fortinet FortiAnalyzer Incident Audit
FortiAnalyzer 7.2.4 local application event records (type=appevent subtype=incident) as ECS JSON with the FortiAnalyzer key-value line in event.original, for SOC teams and SIEM engineers who need incident-management audit trails. This is FortiAnalyzer's own incident audit log, not FortiGate traffic forwarded through it. A SOC of twelve analysts raises about 340 incidents a day, about 225 of them by playbooks, in about 2,050 records a day, with analysts on a 07:00-19:00 UTC day shift and playbooks round the clock. Recurring episodes show an analyst's incident whose evidence a second analyst removes before deleting the incident.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/security-fortinet-fortianalyzer-audit/generator.yml \
--id faz-audit \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| Incident_Update | Incident updated (message ID 100002) | About 47.7% of records | configuration |
| Incident_Attachment_Add | Evidence attached to an incident (message ID 100005) | About 25.5% of records | configuration |
| New_Incident_Create | Incident raised by a playbook or an analyst (message ID 100001) | About 17.6% of records | configuration |
| Incident_Attachment_Delete | Attachment removed from an incident (message ID 100006) | About 6.1% of records | configuration |
| Incident_Delete | Incident deleted (message ID 100003) | About 3.1% of records | configuration |
Realism Features
- Twelve analysts, each with an office and a remote-access address, and playbooks (user=system) raise about 340 incidents a day: about 225 by playbooks and 115 by analysts. Each incident has its own lifecycle: evidence attachments, analyst work sessions of one to several operations, occasional attachment removal, and deletion of about one incident in five, from minutes to days after creation.
- Playbooks raise incidents and attach evidence round the clock with a peak around 13:00 UTC; analysts work a day shift from 07:00 to 19:00 UTC with core hours 09:00-17:00 and a small night shift, and work left at the end of the day continues the next morning. That gives about 26 records an hour from 19:00 to 07:00, about 100 at 07:00-09:00 and 17:00-19:00, and 150-190 at 09:00-17:00. Weekends and holidays look like weekdays.
- An analyst's consecutive operations on one incident are typically 30 seconds to 12 minutes apart (median about 1.5 minutes), and playbook evidence follows its incident within seconds to minutes. About two in five deletions come within an hour of creation, the rest hours to days later. Each analyst keeps the office or the remote-access address for minutes to hours.
- Ordinary traffic holds incidents deleted within minutes, attachments removed by an analyst other than the creator, removal followed by deletion by the same analyst, and handovers where one analyst removes the evidence and a colleague deletes the incident minutes later. The assignee (the creator on an analyst-raised incident) deletes in 60% of cases, otherwise a colleague; when a colleague deletes an analyst-raised incident, the evidence was mostly removed by the creator (50%) or a third analyst (35%).
- Fortinet publishes the INCIDENT field catalog and message IDs but no complete raw incident record. The line copies the header and trailer of the one complete 7.2.4 application log example (id carries itime_t in its upper 32 bits, dtime equals itime, euid, epid, dsteuid and dstepid keep the value 1); the per-message field set, msg text, desc value, IN plus eight digits incident IDs, lowercase severities and event-ID-style attachment values are assumptions, and user_from=GUI(<address>) follows Elastic test fixtures.
- Dates and times are UTC without the tz field, and no Syslog header, CEF form or collector envelope is generated, so compatibility with a FortiAnalyzer collector or a CEF normalizer (for example KUMA's FortiAnalyzer CEF profile) is unverified. The error variants 110001-110006 and Incident_Attachment_Update (100004) are not generated.
- Incident status, category, assignment and notes are not modelled; updates change only the severity, sometimes. With anomaly_mode true each chain adds one analyst-raised incident whose evidence a colleague removes and which that colleague deletes within two hours. Rates, weights, delays and analyst names are synthetic lab settings.
Sample Output
{
"@timestamp": "2026-09-14T09:40:17+00:00",
"ecs": {
"version": "8.17.0"
},
"event": {
"action": "Incident_Attachment_Delete",
"category": [
"configuration"
],
"code": "100006",
"dataset": "fortinet.fortianalyzer.appevent",
"kind": "event",
"original": "id=7685323499194656677 itime=2026-09-14 09:40:17 euid=1 epid=1 dsteuid=1 dstepid=1 vd=root logid=100006 type=appevent subtype=incident level=information date=2026-09-14 time=09:40:17 user=amartin user_from=GUI(10.20.4.21) desc=Incident_Attachment_Delete msg=Attachment deleted from incident IN00000943 incident_id=IN00000943 incident_severity=high attachment=202609141000026412 adom=root devid=FAZ-VMTM26001234 devname=faz-soc-01 dtime=2026-09-14 09:40:17 itime_t=1789378817",
"outcome": "success",
"type": [
"change"
]
},
"fortinet": {
"fortianalyzer": {
"adom": "root",
"attachment": "202609141000026412",
"desc": "Incident_Attachment_Delete",
"incident_id": "IN00000943",
"incident_severity": "high",
"level": "information",
"logid": "100006",
"subtype": "incident",
"type": "appevent",
"user_from": "GUI(10.20.4.21)"
}
},
"observer": {
"name": "faz-soc-01",
"product": "FortiAnalyzer",
"serial_number": "FAZ-VMTM26001234",
"type": "siem",
"vendor": "Fortinet"
},
"related": {
"ip": [
"10.20.4.21"
],
"user": [
"amartin"
]
},
"source": {
"ip": "10.20.4.21"
},
"user": {
"name": "amartin"
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| anomaly_mode | true | Emit the anomaly chain on top of the background |
| anomaly_interval_hours | 24 | Interval between chain starts; range 6-8760 |
| analyzer_serial | FAZ-VMTM26001234 | devid of the FortiAnalyzer unit |
| analyzer_name | faz-soc-01 | devname of the FortiAnalyzer unit |
| adom | root | vd and adom values |
Related Generators
Suricata IDS/IPS
Suricata EVE JSON output — IDS alerts with ET Open signatures, DNS/HTTP/TLS/SSH protocol logs, NetFlow records, and anomaly detections with correlated flow IDs and MITRE ATT&CK mapping.
Palo Alto Threat
Palo Alto PAN-OS Threat logs — IPS vulnerability exploits, antivirus detections, anti-spyware (DNS sinkhole and C2 callback), WildFire cloud verdicts, file type matching, and network scan detection with correlated severity, action, and threat category fields.
Palo Alto URL Filtering
Palo Alto PAN-OS URL Filtering logs — web browsing activity with 65+ URL categories, allow/block/continue/override actions, App-ID application attribution, and content type inspection.