Skip to main content
enguyen3467
Staff
Staff
October 11, 2022

Technical Tip: Disable session start logs

  • October 11, 2022
  • 0 replies
  • 3201 views

Description

This article describes how to disable session start logs.

There are occasions where a user may want to disable the traffic logging on some firewall policies due to the need to see only certain logs on other firewall policies on either FortiGate’s GUI or FortiAnalyzer.


The 'Log Allowed Traffic' option is already set off on the GUI:

 

enguyen3467_0-1665524918759.png

 
However, on the FortiGate or FortiAnalyzer or any other syslog servers, users can still see the messages 'Accept: session start' with the respective firewall policy name and ID associated:

enguyen3467_1-1665524927171.png

date=2026-06-01 time=xx:xx:xx eventtime=1780326670178650102 tz="-0400" logid="0000000015" type="traffic" subtype="forward" level="notice" vd="vd" srcip=x.x.x.x srcport=51362 srcintf=”srcintf" srcintfrole="undefined" dstip=y.y.y.y dstport=10051 dstintf="dstintf" dstintfrole="undefined" srccountry="Reserved" dstcountry="Reserved" sessionid=1043478050 proto=6 action="start" policyid=100 policytype="policy" poluuid="0240d3a8-edd6-51ee-d105-c05dddbf6f1d" policyname="policy" service="tcp/10051" trandisp="noop" appcat="unscanned" duration=0 sentbyte=0 rcvdbyte=0 sentpkt=0 rcvdpkt=0 sla(0x0), gid(1), num of pass(0), selected" vwlname=" vwlname "

Scope

All supported versions of FortiOS.

Solution

In the CLI, disable the following setting in the firewall policy:

config firewall policy
    edit <id>
        set logtraffic-start disable
    next
end

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.