Skip to main content
hrahuman_FTNT
Staff & Editor
Staff & Editor
March 15, 2022

Technical Tip: Difference between 'Security Events' and 'All session' in Log Allowed Traffic in Firewall Policy

  • March 15, 2022
  • 0 replies
  • 17264 views
Description This article describes the difference between 'Security Events' and 'All sessions' in Log Allowed Traffic in Firewall Policy.
Scope FortiGate.
Solution
  • All Sessions: Logs every single connection accepted or denied by the policy, providing a complete record of all traffic flow.
  • Security Events (UTM): Logs only the specific traffic that matches or triggers an active security profile (such as Antivirus, Web Filter, or IPS) applied to the policy.
  • Disable: Prevents the firewall from generating any traffic logs for sessions matching the policy.

To edit the firewall policy logging in the web GUI:

 

gui_screenshot.jpg

 

To edit the firewall policy logging on the CLI:

 

config firewall policy
    edit 1
       set logtraffic {all | utm | disable}
    next
end

 

Related Articles:
Technical Tip: Enable Security Event logging on the policy with Security Fabric enabled 

Logging local traffic per local-in policy | FortiOS 7.6.0 New Features 

Technical Tip: The available options for logging on FortiGate 

 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!