<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: None Authentication in Default Authentication in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/None-Authentication-in-Default-Authentication/m-p/762187#M24399</link>
    <description>&lt;DIV&gt;&lt;P&gt;Yes, we are also seeing issues with the log format introduced by the latest Forti update.&lt;/P&gt;&lt;P&gt;However, the tagging of Forti authentication events with the tags default and authentication is not related to that change and can also be observed in older versions. This behavior appears to have been present for quite some time.&lt;/P&gt;&lt;/DIV&gt;</description>
    <pubDate>Fri, 10 Jul 2026 12:19:50 GMT</pubDate>
    <dc:creator>StehS</dc:creator>
    <dc:date>2026-07-10T12:19:50Z</dc:date>
    <item>
      <title>None Authentication in Default Authentication</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/None-Authentication-in-Default-Authentication/m-p/762103#M24397</link>
      <description>&lt;DIV class=""&gt;&lt;SPAN&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;&lt;SPAN&gt;have you noticed that FortiGate authentication events are tagged with "default" by the Fortinet FortiGate Add-on for Splunk, even when they represent non-default user authentications?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;&lt;SPAN&gt;The Authentication data model expects the tags "authentication" and "default". According to the current tagging in the TA, all authentication-related event types receive the "default" tag:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;&lt;SPAN&gt;default:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; eventtype=ftnt_fortigate_auth&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; eventtype=ftnt_fortigate_vpn_auth&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; eventtype=ftnt_fortigate_wireless_client_authentication&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;&lt;SPAN&gt;My understanding is that the "default" tag should only be applied when the authenticating account is a built-in or default account, such as "admin", "root", or similar.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;&lt;SPAN&gt;Is this the behavior you are seeing as well, or am I misunderstanding the intended CIM mapping?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;&lt;SPAN&gt;Thanks.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 07 Jul 2026 13:15:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/None-Authentication-in-Default-Authentication/m-p/762103#M24397</guid>
      <dc:creator>StehS</dc:creator>
      <dc:date>2026-07-07T13:15:48Z</dc:date>
    </item>
    <item>
      <title>Re: None Authentication in Default Authentication</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/None-Authentication-in-Default-Authentication/m-p/762158#M24398</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/317821"&gt;@StehS&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;Have you been noticing this behavior recently, or was it working fine before? We've seen a few issues lately with FortiAnalyzer deployments after upgrades, so I'm wondering if this started after an upgrade as well.&lt;/DIV&gt;</description>
      <pubDate>Thu, 09 Jul 2026 06:05:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/None-Authentication-in-Default-Authentication/m-p/762158#M24398</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2026-07-09T06:05:30Z</dc:date>
    </item>
    <item>
      <title>Re: None Authentication in Default Authentication</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/None-Authentication-in-Default-Authentication/m-p/762187#M24399</link>
      <description>&lt;DIV&gt;&lt;P&gt;Yes, we are also seeing issues with the log format introduced by the latest Forti update.&lt;/P&gt;&lt;P&gt;However, the tagging of Forti authentication events with the tags default and authentication is not related to that change and can also be observed in older versions. This behavior appears to have been present for quite some time.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 10 Jul 2026 12:19:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/None-Authentication-in-Default-Authentication/m-p/762187#M24399</guid>
      <dc:creator>StehS</dc:creator>
      <dc:date>2026-07-10T12:19:50Z</dc:date>
    </item>
  </channel>
</rss>

