Splunk Enterprise

None Authentication in Default Authentication

StehS
New Member
Hi,

 

have you noticed that FortiGate authentication events are tagged with "default" by the Fortinet FortiGate Add-on for Splunk, even when they represent non-default user authentications?

 

The Authentication data model expects the tags "authentication" and "default". According to the current tagging in the TA, all authentication-related event types receive the "default" tag:

 

default:
    eventtype=ftnt_fortigate_auth
    eventtype=ftnt_fortigate_vpn_auth
    eventtype=ftnt_fortigate_wireless_client_authentication

 

My understanding is that the "default" tag should only be applied when the authenticating account is a built-in or default account, such as "admin", "root", or similar.

 

Is this the behavior you are seeing as well, or am I misunderstanding the intended CIM mapping?

 

Thanks.

 

Labels (1)
0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust

@StehS  

Have you been noticing this behavior recently, or was it working fine before? We've seen a few issues lately with FortiAnalyzer deployments after upgrades, so I'm wondering if this started after an upgrade as well.
Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

StehS
New Member

Yes, we are also seeing issues with the log format introduced by the latest Forti update.

However, the tagging of Forti authentication events with the tags default and authentication is not related to that change and can also be observed in older versions. This behavior appears to have been present for quite some time.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...

Federated Search for CloudWatch Unified Data Store Is Generally Available

As organizations modernize their cloud environments, AWS workloads generate more security, operational, and ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...