cscli parsers install crowdsecurity/fortinet-logs
## Fortinet Logs Parser
Fortinet log parser. More information in Fortinet documentation
1onsuccess: next_stage2#debug: true3filter: "evt.Parsed.program == 'fortinet' && ParseKV(evt.Parsed.message, evt.Unmarshaled, 'fortinet') in [nil, '']"4name: crowdsecurity/fortinet-logs5description: "Parse fortinet logs"6statics:7 - meta: service8 value: fortinet9 - meta: sub_type10 expression: "evt.Unmarshaled.fortinet.subtype"11 - target: evt.StrTime12 expression: evt.Unmarshaled.fortinet.date + ' ' + evt.Unmarshaled.fortinet.time13 - meta: source_ip14 expression: "evt.Unmarshaled.fortinet.remip"15 - meta: action16 expression: "evt.Unmarshaled.fortinet.action"17 - meta: tunnel_type18 expression: "evt.Unmarshaled.fortinet.tunneltype"19 - meta: reason20 expression: "evt.Unmarshaled.fortinet.reason"21 - meta: msg22 expression: "evt.Unmarshaled.fortinet.msg"23 - meta: target_user24 expression: "evt.Unmarshaled.fortinet.user"