Splunk Enterprise

None Authentication in Default Authentication

StehS
New Member
Hi,

 

have you noticed that FortiGate authentication events are tagged with "default" by the Fortinet FortiGate Add-on for Splunk, even when they represent non-default user authentications?

 

The Authentication data model expects the tags "authentication" and "default". According to the current tagging in the TA, all authentication-related event types receive the "default" tag:

 

default:
    eventtype=ftnt_fortigate_auth
    eventtype=ftnt_fortigate_vpn_auth
    eventtype=ftnt_fortigate_wireless_client_authentication

 

My understanding is that the "default" tag should only be applied when the authenticating account is a built-in or default account, such as "admin", "root", or similar.

 

Is this the behavior you are seeing as well, or am I misunderstanding the intended CIM mapping?

 

Thanks.

 

Labels (1)
0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust

@StehS  

Have you been noticing this behavior recently, or was it working fine before? We've seen a few issues lately with FortiAnalyzer deployments after upgrades, so I'm wondering if this started after an upgrade as well.
Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

StehS
New Member

Yes, we are also seeing issues with the log format introduced by the latest Forti update.

However, the tagging of Forti authentication events with the tags default and authentication is not related to that change and can also be observed in older versions. This behavior appears to have been present for quite some time.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Splunk is excited to announce the General Availability (GA) of Federated Search for ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...