Splunk Enterprise

None Authentication in Default Authentication

StehS
New Member
Hi,

 

have you noticed that FortiGate authentication events are tagged with "default" by the Fortinet FortiGate Add-on for Splunk, even when they represent non-default user authentications?

 

The Authentication data model expects the tags "authentication" and "default". According to the current tagging in the TA, all authentication-related event types receive the "default" tag:

 

default:
    eventtype=ftnt_fortigate_auth
    eventtype=ftnt_fortigate_vpn_auth
    eventtype=ftnt_fortigate_wireless_client_authentication

 

My understanding is that the "default" tag should only be applied when the authenticating account is a built-in or default account, such as "admin", "root", or similar.

 

Is this the behavior you are seeing as well, or am I misunderstanding the intended CIM mapping?

 

Thanks.

 

Labels (1)
0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust

@StehS  

Have you been noticing this behavior recently, or was it working fine before? We've seen a few issues lately with FortiAnalyzer deployments after upgrades, so I'm wondering if this started after an upgrade as well.
Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

StehS
New Member

Yes, we are also seeing issues with the log format introduced by the latest Forti update.

However, the tagging of Forti authentication events with the tags default and authentication is not related to that change and can also be observed in older versions. This behavior appears to have been present for quite some time.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...