FortiGate sends its logs to Wazuh, failed admin logins show up, and denied traffic does not. On Wazuh 4.14.7 that is the stock ruleset working as written. We measured it, plus a second problem that only shows up with CSV syslog.
Setup: FortiOS-style key=value lines sent over UDP syslog to a Wazuh 4.14.7 manager container; we read alerts.json.
Reason 1: every traffic log stops at level 1
In ruleset/rules/0391-fortigate_rules.xml, rule 81618 matches any FortiGate log with type=traffic at level 1. It does not look at action, so denied and allowed sessions land on the same rule. The default <log_alert_level> in ossec.conf is 3, and nothing below it is written to alerts.json. The only traffic rule above the line is 81619, level 3, after 18 traffic events from one source within 45 seconds.
We sent one denied forward session (action="deny", SSH from outside to an internal host) and one Admin login failed event:
| Event | Rule | Level | In alerts.json? |
|---|---|---|---|
traffic, action="deny"
|
81618 | 1 | no |
| admin login failed | 81606 | 4 | yes |
Reason 2: CSV format corrupts srcip
The stock decoder reads key=value pairs separated by spaces. In CSV format the separator is a comma, so the capture for srcip runs to the next space. The same login-failed event in CSV produced an alert whose data.srcip was:
203.0.113.5,dstip=192.168.1.99,action="login",status="failed",...
The rule still fires, but GeoIP, <same_source_ip> correlation and the firewall-drop active response all read that field.
The fix
- Send the default format for the syslog server Wazuh listens on:
config log syslogd setting
set format default
end
-
Raise denied traffic to an alert in
/var/ossec/etc/rules/local_rules.xml:
<group name="local,fortigate,">
<rule id="100210" level="5">
<if_sid>81618</if_sid>
<action>deny</action>
<description>FortiGate: traffic denied by policy.</description>
<group>firewall_block,</group>
</rule>
</group>
On 4.14.7 the same denied line that produced nothing produced a level 5 alert with srcip and dstport intact. Narrow it (interface, port, destination) if an internet-facing firewall makes it too loud.
Use the <action> tag, not <field name="action">. action is a static field. With the <field> form, 4.14.7 logged ERROR: Failure to read rule 100210. Field 'action' is static. and the manager did not start, so there were no alerts at all, not only for FortiGate.
Limits
Measured on a Wazuh 4.14.7 manager container (syslog over UDP 514, and wazuh-logtest). We did not run a FortiGate: the lines were written in the FortiOS key=value layout and converted to CSV by changing the separator. Not measured: cef and rfc5424 formats, UTM/VPN/IPS logs, other versions. The CLI syntax is from Fortinet's config log syslogd setting reference, not run on a device.
Full note with the one-minute checks: https://atkvn.com/fix-fortigate-logs-not-showing-in-wazuh.html
Dong Nguyen, ATK New Technology. We check and fix Wazuh rules for people who run it.
Top comments (0)