NSE4 · Question #522
What attributes are always included in a log header? (Choose three.)
The correct answer is B. level D. time E. subtype. FortiGate log headers consistently include the log level (severity), the time of the event, and the subtype (category of the log message) for consistent event identification.
Question
What attributes are always included in a log header? (Choose three.)
Options
- Apolicyid
- Blevel
- Cuser
- Dtime
- Esubtype
- Fduration
How the community answered
(28 responses)- A4% (1)
- B93% (26)
- C4% (1)
Why each option
FortiGate log headers consistently include the log `level` (severity), the `time` of the event, and the `subtype` (category of the log message) for consistent event identification.
Policy ID is specific to traffic logs and not present in all log types (e.g., system events, administrative logs).
The `level` attribute specifies the severity of the log message, which is fundamental for log management and alerting.
User information is present in logs related to user authentication or activity, but not universally in all log headers across all log types.
The `time` attribute records when the event occurred, which is essential for chronological analysis and correlation of events.
The `subtype` attribute categorizes the type of log message (e.g., traffic, event, virus, attack), providing essential context for interpretation.
Duration is specific to session-based logs like traffic logs, indicating the length of a connection, and is not a universal header attribute.
Concept tested: FortiGate log structure and attributes
Source: https://docs.fortinet.com/document/fortigate/7.4.0/fortios-log-message-reference/700030/process-messages
Topics
Community Discussion
No community discussion yet for this question.