<group name="fortigate,syslog,">
<rule id="100100" level="0">
<decoded_as>fortigate-firewall-v5</decoded_as>
<description>XXX firewall messages grouped.</description>
</rule>
<rule id="100101" level="0">
<if_sid>100100</if_sid>
<match>subtype=ips</match>
<description>XXX IPS messages grouped.</description>
</rule>
<!-- Ignore XXX -->
<rule id="100102" level="0">
<if_sid>100101</if_sid>
<match>srcip=X.X.X.X|srcip=X.X.X.X</match>
<description>XXX IPS XXX messages grouped.</description>
</rule>
<!-- Ignore XXX -->
<rule id="100103" level="0">
<if_sid>100101</if_sid>
<srcip>!X.X.X.X/19</srcip>
<dstip>!X.X.X.X/19</dstip>
<description>X.X.X.X IPS XXX messages grouped.</description>
</rule>
<!-- Rules for firewall back. ID: 100110 to 100140 -->
<rule id="100111" level="0">
<if_sid>100101</if_sid>
<match>devname=XXX|devname=XXX</match>
<description>XXX firewall back messages grouped.</description>
</rule>
<rule id="100112" level="3">
<if_sid>100111</if_sid>
<match>severity=information</match>
<description>XXX IPS back information messages.</description>
</rule>
<rule id="100113" level="5">
<if_sid>100111</if_sid>
<match>severity=low</match>
<description>XXX IPS back low messages.</description>
</rule>
<rule id="100114" level="8">
<if_sid>100111</if_sid>
<match>severity=medium</match>
<description>XXX IPS back medium messages.</description>
</rule>
<rule id="100115" level="11">
<if_sid>100111</if_sid>
<match>severity=high</match>
<description>XXX IPS back high messages.</description>
</rule>
<rule id="100116" level="15">
<if_sid>100111</if_sid>
<match>severity=critical</match>
<description>XXX IPS back critical messages.</description>
</rule>
.....