bokamba / loganvil / FortiGate firewall logs

$ loganvil generate fortigate

Generate synthetic FortiGate firewall logs

Generate realistic synthetic FortiGate firewall traffic logs (key=value / FortiOS format) for pipeline testing, SIEM demos, and detection tuning — deterministic and 100% client-side. Each line is a real FortiOS traffic log — date, devname, logid, type/subtype, srcip/srcport, dstip/dstport, action, service, sentbyte/rcvdbyte — so it round-trips through a FortiGate parser. No real network or secrets.

Open the LogAnvil generator →

This sample, generated

The block below is 15 lines of FortiGate firewall logs, produced by the real generator at seed 42 — deterministic, so this exact output regenerates anywhere. The live tool re-runs the identical engine on whatever source, seed, line count and anomalies you pick.

15lines
4.5stime span
0anomaly lines
42seed

no anomalies injected — raise a slider to seed detectable patterns

Generated FortiGate firewall logs

Real on-the-wire FortiGate firewall logs — no real users, IPs, or secrets. Copy it into a fixture, feed it to a parser, or seed a SIEM demo.

date=2020-09-13T12:26:40.000Z devname="FGT60F" devid="FGT60FTK20012345" logid="0000000013" type="traffic" subtype="forward" level="notice" srcip=192.168.0.101 srcport=45424 dstip=185.199.108.153 dstport=993 action="accept" service="SSH" sentbyte=54645 rcvdbyte=124949
date=2020-09-13T12:26:40.431Z devname="FGT60F" devid="FGT60FTK20012345" logid="0000000013" type="traffic" subtype="forward" level="notice" srcip=172.16.31.77 srcport=39823 dstip=185.199.108.153 dstport=995 action="deny" service="HTTPS" sentbyte=100146 rcvdbyte=137323
date=2020-09-13T12:26:40.794Z devname="FGT60F" devid="FGT60FTK20012345" logid="0000000013" type="traffic" subtype="forward" level="notice" srcip=10.0.0.5 srcport=46059 dstip=185.199.108.153 dstport=21 action="close" service="HTTPS" sentbyte=53391 rcvdbyte=12356
date=2020-09-13T12:26:41.044Z devname="FGT60F" devid="FGT60FTK20012345" logid="0000000013" type="traffic" subtype="forward" level="notice" srcip=192.168.1.133 srcport=47740 dstip=8.8.8.8 dstport=23 action="timeout" service="SSH" sentbyte=161805 rcvdbyte=63892
date=2020-09-13T12:26:41.364Z devname="FGT60F" devid="FGT60FTK20012345" logid="0000000013" type="traffic" subtype="forward" level="notice" srcip=10.0.0.5 srcport=34218 dstip=13.107.42.14 dstport=465 action="accept" service="DNS" sentbyte=41902 rcvdbyte=60726
date=2020-09-13T12:26:41.761Z devname="FGT60F" devid="FGT60FTK20012345" logid="0000000013" type="traffic" subtype="forward" level="notice" srcip=192.168.10.7 srcport=47109 dstip=104.16.132.229 dstport=53 action="deny" service="HTTPS" sentbyte=131972 rcvdbyte=136154
date=2020-09-13T12:26:42.146Z devname="FGT60F" devid="FGT60FTK20012345" logid="0000000013" type="traffic" subtype="forward" level="notice" srcip=192.168.100.254 srcport=35251 dstip=93.184.216.34 dstport=143 action="timeout" service="HTTPS" sentbyte=22188 rcvdbyte=3168
date=2020-09-13T12:26:42.442Z devname="FGT60F" devid="FGT60FTK20012345" logid="0000000013" type="traffic" subtype="forward" level="notice" srcip=172.16.31.77 srcport=50043 dstip=185.199.108.153 dstport=21 action="close" service="SMTP" sentbyte=55650 rcvdbyte=141317
date=2020-09-13T12:26:42.690Z devname="FGT60F" devid="FGT60FTK20012345" logid="0000000013" type="traffic" subtype="forward" level="notice" srcip=172.20.0.15 srcport=55971 dstip=1.1.1.1 dstport=8443 action="close" service="SMTP" sentbyte=86798 rcvdbyte=115691
date=2020-09-13T12:26:42.980Z devname="FGT60F" devid="FGT60FTK20012345" logid="0000000013" type="traffic" subtype="forward" level="notice" srcip=192.168.0.101 srcport=41885 dstip=34.223.14.100 dstport=80 action="deny" service="SMTP" sentbyte=139013 rcvdbyte=198803
date=2020-09-13T12:26:43.417Z devname="FGT60F" devid="FGT60FTK20012345" logid="0000000013" type="traffic" subtype="forward" level="notice" srcip=172.16.31.77 srcport=48160 dstip=104.16.132.229 dstport=22 action="close" service="HTTP" sentbyte=157189 rcvdbyte=180956
date=2020-09-13T12:26:43.642Z devname="FGT60F" devid="FGT60FTK20012345" logid="0000000013" type="traffic" subtype="forward" level="notice" srcip=172.16.31.77 srcport=55973 dstip=1.1.1.1 dstport=8443 action="accept" service="DNS" sentbyte=139938 rcvdbyte=44636
date=2020-09-13T12:26:43.952Z devname="FGT60F" devid="FGT60FTK20012345" logid="0000000013" type="traffic" subtype="forward" level="notice" srcip=10.0.1.24 srcport=51250 dstip=140.82.113.4 dstport=25 action="close" service="SMTP" sentbyte=65275 rcvdbyte=158486
date=2020-09-13T12:26:44.257Z devname="FGT60F" devid="FGT60FTK20012345" logid="0000000013" type="traffic" subtype="forward" level="notice" srcip=10.0.1.24 srcport=57152 dstip=140.82.113.4 dstport=20 action="close" service="DNS" sentbyte=175185 rcvdbyte=181633
date=2020-09-13T12:26:44.513Z devname="FGT60F" devid="FGT60FTK20012345" logid="0000000013" type="traffic" subtype="forward" level="notice" srcip=192.168.0.101 srcport=46580 dstip=1.1.1.1 dstport=20 action="close" service="DNS" sentbyte=58298 rcvdbyte=55097

With an anomaly injected: Port scan

The same source, regenerated with a Port scan injected at 30% intensity. 7 line sare tagged and highlighted below — One source IP hitting many sequential destination ports — reconnaissance sweeping for open services. It is a documented, detectable pattern your SIEM rules should fire on — build the test data, then prove your detection works.

date=2020-09-13T12:26:40.000Z devname="FGT60F" devid="FGT60FTK20012345" logid="0000000013" type="traffic" subtype="forward" level="notice" srcip=192.168.0.101 srcport=45424 dstip=185.199.108.153 dstport=993 action="accept" service="SSH" sentbyte=54645 rcvdbyte=124949
date=2020-09-13T12:26:40.431Z devname="FGT60F" devid="FGT60FTK20012345" logid="0000000013" type="traffic" subtype="forward" level="notice" srcip=172.16.31.77 srcport=39823 dstip=185.199.108.153 dstport=995 action="deny" service="HTTPS" sentbyte=100146 rcvdbyte=137323
date=2020-09-13T12:26:40.794Z devname="FGT60F" devid="FGT60FTK20012345" logid="0000000013" type="traffic" subtype="forward" level="notice" srcip=10.0.0.5 srcport=46059 dstip=185.199.108.153 dstport=21 action="close" service="HTTPS" sentbyte=53391 rcvdbyte=12356
date=2020-09-13T12:26:41.044Z devname="FGT60F" devid="FGT60FTK20012345" logid="0000000013" type="traffic" subtype="forward" level="notice" srcip=192.168.1.133 srcport=47740 dstip=8.8.8.8 dstport=23 action="timeout" service="SSH" sentbyte=161805 rcvdbyte=63892
date=2020-09-13T12:26:41.364Z devname="FGT60F" devid="FGT60FTK20012345" logid="0000000013" type="traffic" subtype="forward" level="notice" srcip=10.0.0.5 srcport=34218 dstip=13.107.42.14 dstport=465 action="accept" service="DNS" sentbyte=41902 rcvdbyte=60726
date=2020-09-13T12:26:41.761Z devname="FGT60F" devid="FGT60FTK20012345" logid="0000000013" type="traffic" subtype="forward" level="notice" srcip=192.168.10.7 srcport=47109 dstip=104.16.132.229 dstport=53 action="deny" service="HTTPS" sentbyte=131972 rcvdbyte=136154
date=2020-09-13T12:26:42.146Z devname="FGT60F" devid="FGT60FTK20012345" logid="0000000013" type="traffic" subtype="forward" level="notice" srcip=192.168.100.254 srcport=35251 dstip=93.184.216.34 dstport=143 action="timeout" service="HTTPS" sentbyte=22188 rcvdbyte=3168
date=2020-09-13T12:26:42.442Z devname="FGT60F" devid="FGT60FTK20012345" logid="0000000013" type="traffic" subtype="forward" level="notice" srcip=172.16.31.77 srcport=50043 dstip=185.199.108.153 dstport=21 action="close" service="SMTP" sentbyte=55650 rcvdbyte=141317
srcip=193.106.191.19 dstip=203.0.113.209 dstport=121 action=deny sentbyte=120Port scan
srcip=193.106.191.19 dstip=203.0.113.209 dstport=122 action=deny sentbyte=85Port scan
srcip=193.106.191.19 dstip=203.0.113.209 dstport=123 action=deny sentbyte=114Port scan
srcip=193.106.191.19 dstip=203.0.113.209 dstport=124 action=deny sentbyte=75Port scan
srcip=193.106.191.19 dstip=203.0.113.209 dstport=125 action=deny sentbyte=86Port scan
srcip=193.106.191.19 dstip=203.0.113.209 dstport=126 action=deny sentbyte=67Port scan
srcip=193.106.191.19 dstip=203.0.113.209 dstport=127 action=deny sentbyte=88Port scan

FAQ

Are these real FortiGate logs?
No — the output is synthetic. It reproduces the FortiOS key=value traffic-log format (down to the devname/logid/type fields), but every IP, port and byte count is fabricated. Safe for fixtures, demos and parser tests.
Can I inject anomalies?
Yes. A port scan is the natural fit here: the slider appends a sweep of one source IP hitting many sequential destination ports with tiny byte counts, in faithful key=value grammar. Injected lines are highlighted and badged so you can prove your scan detection fires.
Is the output deterministic?
Yes — fully seeded. The same seed and config always produce byte-identical FortiGate lines, so a committed seed regenerates the exact same firewall log anywhere.

Generate other log sources

Open the LogAnvil generator to tune the seed, line count, EPS, format and anomaly sliders — or build a parser with LogForge for a log you already have.

Generate your own FortiGate firewall logs

Pick the seed, line count and EPS, inject the anomalies your rules should catch, and copy or download the result. Free, no account, nothing uploaded — generation runs entirely in your browser.

Open the LogAnvil generator →