---
title: "cef0.fortinet"
canonical: "https://docs.devo.com/space/latest/413630529/cef0.fortinet"
format: markdown
---
[ [Introduction](https://devodocs.atlassian.net/wiki/spaces/latest/pages/397901825/cef0.forcepoint#Introduction) ] [ [Tag structure](https://devodocs.atlassian.net/wiki/spaces/latest/pages/397901825/cef0.forcepoint#Tag-structure) ] [ [How is the data sent to Devo?](https://devodocs.atlassian.net/wiki/spaces/latest/pages/397901825/cef0.forcepoint#How-is-the-data-sent-to-Devo?) ] [ [Table structure](https://devodocs.atlassian.net/wiki/spaces/latest/pages/397901825/cef0.forcepoint#Table-structure) ]

## Purpose

The tags beginning with `cef0.fortinet` identify events in CEF format generated by [Fortinet](https://www.fortinet.com/) devices.  These include firewall and identity and access management devices.

Many Fortinet data sources do not use CEF format.  For comma separated and space separated firewall logs, use [firewall.fortinet](https://devodocs.atlassian.net/wiki/spaces/latest/pages/94663604).  For Fortinet [email security](https://www.fortinet.com/products/email-security), use [mail.fortinet](https://devodocs.atlassian.net/wiki/spaces/latest/pages/356679723).  For Fortinet [identity management](https://www.fortinet.com/solutions/enterprise-midsize-business/identity-access-management), use [iam.fortinet](https://devodocs.atlassian.net/wiki/spaces/latest/pages/370475009).

## Sent it

CEF data can be sent directly to Devo or by using a relay. To use the [CEF default relay rule](https://docs.devo.com/space/latest/96469422/The+4+predefined+relay+rules), send to the relay’s port **13000**. Learn more about CEF syslog format and how Devo tags these events in [Technologies supported in CEF syslog format](https://docs.devo.com/space/latest/94666383/Technologies+supported+in+CEF+syslog+format).

## Secure it

Use the security resources for [firewall.all.traffic](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95126157/firewall.all.traffic#Secure-it) to secure Fortigate data.

## Tags and tables

The cef0.fortinet.fortigateAll and firewall.all.traffic tables contain all the other FortiGate CEF tables.

| **[Tags](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95126204)** | **[Tables](https://devodocs.atlassian.net/wiki/spaces/latest/pages/94764298)** |
| --- | --- |
|  | cef0.fortinet.fortigateAll |
| cef0.fortinet.fortiauthenticator | cef0.fortinet.fortiauthenticator |
| cef0.fortinet.fortigate | cef0.fortinet.fortigate |
| cef0.fortinet.fortigate100e | cef0.fortinet.fortigate100e |
| cef0.fortinet.fortigate100f | cef0.fortinet.fortigate100f |
| cef0.fortinet.fortigate200e | cef0.fortinet.fortigate200e |
| cef0.fortinet.fortigate200f | cef0.fortinet.fortigate200f |
| cef0.fortinet.fortigate300d | cef0.fortinet.fortigate300d |
| cef0.fortinet.fortigate400e | cef0.fortinet.fortigate400e |
| cef0.fortinet.fortigate500e | cef0.fortinet.fortigate500e |
| cef0.fortinet.fortigate600e | cef0.fortinet.fortigate600e |
| cef0.fortinet.fortigate60e | cef0.fortinet.fortigate60e |
| cef0.fortinet.fortinacVmCa | cef0.fortinet.fortinacVmCa |
| cef0.fortinet.fortiwifi60e | cef0.fortinet.fortiwifi60e |