Splunk Enterprise

None Authentication in Default Authentication

StehS
New Member
Hi,

 

have you noticed that FortiGate authentication events are tagged with "default" by the Fortinet FortiGate Add-on for Splunk, even when they represent non-default user authentications?

 

The Authentication data model expects the tags "authentication" and "default". According to the current tagging in the TA, all authentication-related event types receive the "default" tag:

 

default:
    eventtype=ftnt_fortigate_auth
    eventtype=ftnt_fortigate_vpn_auth
    eventtype=ftnt_fortigate_wireless_client_authentication

 

My understanding is that the "default" tag should only be applied when the authenticating account is a built-in or default account, such as "admin", "root", or similar.

 

Is this the behavior you are seeing as well, or am I misunderstanding the intended CIM mapping?

 

Thanks.

 

Labels (1)
0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust

@StehS  

Have you been noticing this behavior recently, or was it working fine before? We've seen a few issues lately with FortiAnalyzer deployments after upgrades, so I'm wondering if this started after an upgrade as well.
Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

StehS
New Member

Yes, we are also seeing issues with the log format introduced by the latest Forti update.

However, the tagging of Forti authentication events with the tags default and authentication is not related to that change and can also be observed in older versions. This behavior appears to have been present for quite some time.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Automated Threat Analysis: Available in ES Premier

Automated Threat Analysis: Centralize and Accelerate Phishing Investigations in Splunk Enterprise ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...