DEV Community

Nguyen Dong
Nguyen Dong

Posted on

FortiGate denied traffic never reaches the Wazuh dashboard. Rule 81618 is level 1.

FortiGate sends its logs to Wazuh, failed admin logins show up, and denied traffic does not. On Wazuh 4.14.7 that is the stock ruleset working as written. We measured it, plus a second problem that only shows up with CSV syslog.

Setup: FortiOS-style key=value lines sent over UDP syslog to a Wazuh 4.14.7 manager container; we read alerts.json.

Reason 1: every traffic log stops at level 1

In ruleset/rules/0391-fortigate_rules.xml, rule 81618 matches any FortiGate log with type=traffic at level 1. It does not look at action, so denied and allowed sessions land on the same rule. The default <log_alert_level> in ossec.conf is 3, and nothing below it is written to alerts.json. The only traffic rule above the line is 81619, level 3, after 18 traffic events from one source within 45 seconds.

We sent one denied forward session (action="deny", SSH from outside to an internal host) and one Admin login failed event:

Event Rule Level In alerts.json?
traffic, action="deny" 81618 1 no
admin login failed 81606 4 yes

Reason 2: CSV format corrupts srcip

The stock decoder reads key=value pairs separated by spaces. In CSV format the separator is a comma, so the capture for srcip runs to the next space. The same login-failed event in CSV produced an alert whose data.srcip was:

203.0.113.5,dstip=192.168.1.99,action="login",status="failed",...
Enter fullscreen mode Exit fullscreen mode

The rule still fires, but GeoIP, <same_source_ip> correlation and the firewall-drop active response all read that field.

The fix

  1. Send the default format for the syslog server Wazuh listens on:
config log syslogd setting
    set format default
end
Enter fullscreen mode Exit fullscreen mode
  1. Raise denied traffic to an alert in /var/ossec/etc/rules/local_rules.xml:
<group name="local,fortigate,">
  <rule id="100210" level="5">
    <if_sid>81618</if_sid>
    <action>deny</action>
    <description>FortiGate: traffic denied by policy.</description>
    <group>firewall_block,</group>
  </rule>
</group>
Enter fullscreen mode Exit fullscreen mode

On 4.14.7 the same denied line that produced nothing produced a level 5 alert with srcip and dstport intact. Narrow it (interface, port, destination) if an internet-facing firewall makes it too loud.

Use the <action> tag, not <field name="action">. action is a static field. With the <field> form, 4.14.7 logged ERROR: Failure to read rule 100210. Field 'action' is static. and the manager did not start, so there were no alerts at all, not only for FortiGate.

Limits

Measured on a Wazuh 4.14.7 manager container (syslog over UDP 514, and wazuh-logtest). We did not run a FortiGate: the lines were written in the FortiOS key=value layout and converted to CSV by changing the separator. Not measured: cef and rfc5424 formats, UTM/VPN/IPS logs, other versions. The CLI syntax is from Fortinet's config log syslogd setting reference, not run on a device.

Full note with the one-minute checks: https://atkvn.com/fix-fortigate-logs-not-showing-in-wazuh.html

Dong Nguyen, ATK New Technology. We check and fix Wazuh rules for people who run it.

Top comments (0)