FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
ssriswadpong
Staff
Staff
Article Id 312977

 

Description This article describes how to fix the error 'Invalid field' when running 'execute log filter field'.
Scope FortiGate, FortiProxy.
Solution

Some fields are only available in a specific category. Category must be selected to filter some fields.

 

For example:

 

FortiGate # execute log filter field advpnsc 0
Invalid field: advpnsc

 

The error 'Invalid field' will be returned because 'advpnsc' is not available for all categories. The category must be selected first.

 

FortiGate # execute log filter category 1

FortiGate # execute log filter field advpnsc 0

FortiGate # execute log display

1: date=2024-05-01 time=12:35:01 eventtime=1714592101467463743 tz="-0700" logid="0101037134" type="event" subtype="vpn" level="notice" vd="root" logdesc="IPsec phase 1 SA deleted" msg="delete IPsec phase 1 SA" action="delete_phase1_sa" remip=10.227.1.243 locip=10.227.2.143 remport=500 locport=500 outintf="port4" cookies="126a83d563dd3280/48bbd75bfa4f983a" user="10.227.1.243" group="N/A" useralt="N/A" xauthuser="N/A" xauthgroup="N/A" assignip=N/A vpntunnel="Hub-to-Spoke" fctuid="N/A" advpnsc=0

2: date=2024-05-01 time=12:35:01 eventtime=1714592101466884806 tz="-0700" logid="0101037139" type="event" subtype="vpn" level="notice" vd="root" logdesc="IPsec phase 2 status changed" msg="IPsec phase 2 status change" action="phase2-down" remip=10.227.1.243 locip=10.227.2.143 remport=500 locport=500 outintf="port4" srccountry="Reserved" cookies="126a83d563dd3280/48bbd75bfa4f983a" user="10.227.1.243" group="N/A" useralt="N/A" xauthuser="N/A" xauthgroup="N/A" assignip=N/A vpntunnel="Hub-to-Spoke_0" phase2_name="Hub-to-Spoke" fctuid="N/A" advpnsc=0


After selecting category 1 (System events), the field can be selected.