What Changed
Fortigate ASIM parser updates to address field name inconsistencies that were impacting schema compliance for ASIM tables. The changes originated from PR #12794 and ensure proper data normalization.
Parser Impact
Field mapping corrections ensure that Fortigate network session logs properly align with ASIM NetworkSession schema requirements. This addresses data fidelity issues where field names may have been inconsistent with the normalized schema specification.
Additional Content
This PR includes the same extensive Microsoft 365 Defender Email and Collaboration hunting queries as previous updates, indicating this was part of a consolidated release addressing multiple improvements.
Security Impact (Visibility & Fidelity)
Organizations using Fortigate firewalls with ASIM normalization will see improved query reliability when referencing standardized field names. Previously inconsistent field mappings could have caused detection rules or hunting queries to miss data due to schema mismatches.
Affected Files
Parsers/ASimNetworkSession/ARM/ASimNetworkSessionFortinetFortiGate/ (ASIM parser + ARM template)
700+ Microsoft 365 Defender Email and Collaboration hunting queries
Custom table test definitions for schema validation