Hub
Security

Fortinet FortiAnalyzer Incident Audit

FortiAnalyzer 7.2.4 local application event records (type=appevent subtype=incident) as ECS JSON with the FortiAnalyzer key-value line in event.original, for SOC teams and SIEM engineers who need incident-management audit trails. This is FortiAnalyzer's own incident audit log, not FortiGate traffic forwarded through it. A SOC of twelve analysts raises about 340 incidents a day, about 225 of them by playbooks, in about 2,050 records a day, with analysts on a 07:00-19:00 UTC day shift and playbooks round the clock. Recurring episodes show an analyst's incident whose evidence a second analyst removes before deleting the incident.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/security-fortinet-fortianalyzer-audit/generator.yml \
  --id faz-audit \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
Incident_UpdateIncident updated (message ID 100002)About 47.7% of recordsconfiguration
Incident_Attachment_AddEvidence attached to an incident (message ID 100005)About 25.5% of recordsconfiguration
New_Incident_CreateIncident raised by a playbook or an analyst (message ID 100001)About 17.6% of recordsconfiguration
Incident_Attachment_DeleteAttachment removed from an incident (message ID 100006)About 6.1% of recordsconfiguration
Incident_DeleteIncident deleted (message ID 100003)About 3.1% of recordsconfiguration

Realism Features

  • Twelve analysts, each with an office and a remote-access address, and playbooks (user=system) raise about 340 incidents a day: about 225 by playbooks and 115 by analysts. Each incident has its own lifecycle: evidence attachments, analyst work sessions of one to several operations, occasional attachment removal, and deletion of about one incident in five, from minutes to days after creation.
  • Playbooks raise incidents and attach evidence round the clock with a peak around 13:00 UTC; analysts work a day shift from 07:00 to 19:00 UTC with core hours 09:00-17:00 and a small night shift, and work left at the end of the day continues the next morning. That gives about 26 records an hour from 19:00 to 07:00, about 100 at 07:00-09:00 and 17:00-19:00, and 150-190 at 09:00-17:00. Weekends and holidays look like weekdays.
  • An analyst's consecutive operations on one incident are typically 30 seconds to 12 minutes apart (median about 1.5 minutes), and playbook evidence follows its incident within seconds to minutes. About two in five deletions come within an hour of creation, the rest hours to days later. Each analyst keeps the office or the remote-access address for minutes to hours.
  • Ordinary traffic holds incidents deleted within minutes, attachments removed by an analyst other than the creator, removal followed by deletion by the same analyst, and handovers where one analyst removes the evidence and a colleague deletes the incident minutes later. The assignee (the creator on an analyst-raised incident) deletes in 60% of cases, otherwise a colleague; when a colleague deletes an analyst-raised incident, the evidence was mostly removed by the creator (50%) or a third analyst (35%).
  • Fortinet publishes the INCIDENT field catalog and message IDs but no complete raw incident record. The line copies the header and trailer of the one complete 7.2.4 application log example (id carries itime_t in its upper 32 bits, dtime equals itime, euid, epid, dsteuid and dstepid keep the value 1); the per-message field set, msg text, desc value, IN plus eight digits incident IDs, lowercase severities and event-ID-style attachment values are assumptions, and user_from=GUI(<address>) follows Elastic test fixtures.
  • Dates and times are UTC without the tz field, and no Syslog header, CEF form or collector envelope is generated, so compatibility with a FortiAnalyzer collector or a CEF normalizer (for example KUMA's FortiAnalyzer CEF profile) is unverified. The error variants 110001-110006 and Incident_Attachment_Update (100004) are not generated.
  • Incident status, category, assignment and notes are not modelled; updates change only the severity, sometimes. With anomaly_mode true each chain adds one analyst-raised incident whose evidence a colleague removes and which that colleague deletes within two hours. Rates, weights, delays and analyst names are synthetic lab settings.

Sample Output

{
  "@timestamp": "2026-09-14T09:40:17+00:00",
  "ecs": {
    "version": "8.17.0"
  },
  "event": {
    "action": "Incident_Attachment_Delete",
    "category": [
      "configuration"
    ],
    "code": "100006",
    "dataset": "fortinet.fortianalyzer.appevent",
    "kind": "event",
    "original": "id=7685323499194656677 itime=2026-09-14 09:40:17 euid=1 epid=1 dsteuid=1 dstepid=1 vd=root logid=100006 type=appevent subtype=incident level=information date=2026-09-14 time=09:40:17 user=amartin user_from=GUI(10.20.4.21) desc=Incident_Attachment_Delete msg=Attachment deleted from incident IN00000943 incident_id=IN00000943 incident_severity=high attachment=202609141000026412 adom=root devid=FAZ-VMTM26001234 devname=faz-soc-01 dtime=2026-09-14 09:40:17 itime_t=1789378817",
    "outcome": "success",
    "type": [
      "change"
    ]
  },
  "fortinet": {
    "fortianalyzer": {
      "adom": "root",
      "attachment": "202609141000026412",
      "desc": "Incident_Attachment_Delete",
      "incident_id": "IN00000943",
      "incident_severity": "high",
      "level": "information",
      "logid": "100006",
      "subtype": "incident",
      "type": "appevent",
      "user_from": "GUI(10.20.4.21)"
    }
  },
  "observer": {
    "name": "faz-soc-01",
    "product": "FortiAnalyzer",
    "serial_number": "FAZ-VMTM26001234",
    "type": "siem",
    "vendor": "Fortinet"
  },
  "related": {
    "ip": [
      "10.20.4.21"
    ],
    "user": [
      "amartin"
    ]
  },
  "source": {
    "ip": "10.20.4.21"
  },
  "user": {
    "name": "amartin"
  }
}

Parameters

ParameterDefaultDescription
anomaly_modetrueEmit the anomaly chain on top of the background
anomaly_interval_hours24Interval between chain starts; range 6-8760
analyzer_serialFAZ-VMTM26001234devid of the FortiAnalyzer unit
analyzer_namefaz-soc-01devname of the FortiAnalyzer unit
adomrootvd and adom values

Related Generators