Skip to main content
auppal
Staff
Staff
August 9, 2022

Technical Tip: Enable Security Event logging on policy with Security Fabric enabled

  • August 9, 2022
  • 0 replies
  • 14054 views
Description

This article describes how to enable Security Event logging when Security Fabric is enabled.

It applies to both Fabric root and subordinate FortiGates.

 

When the FortiGates are a part of a security Fabric, then logging is by default set to 'All Session' logging.

Users cannot directly change the logging to the Security Events as the option is greyed out.

In some networks, it might be required to log only Security Events to avoid generating too many logs as a result of all sessions.

 

As shown below, the security fabric is enabled, and local FortiGate is the Fabric root:

  MicrosoftTeams-image (53).png

 

In the policy, the option to select Security Event logging is greyed out, as shown below.

 

When the info indication is hovered over, it shows: 'security fabric is enabled so logging will exempt traffic from downstream FortiGates'.

 

MicrosoftTeams-image (54).png

 

Although the CLI will give us an option to select the log traffic to 'UTM', it will never change it in the GUI and will continue to log all traffic.

MicrosoftTeams-image (55).png

 

MicrosoftTeams-image (56).png

 MicrosoftTeams-image (57).png

Scope FortiGate.
Solution

To resolve this, set the configuration-sync to use 'local' instead of the 'default'. This can be achieved as shown below:

 

MicrosoftTeams-image (58).png

 

After making the change, set the logging to Security Events from the GUI:

 

MicrosoftTeams-image (59).png

 

Note: There are 2 options that configuration-sync can be set to, which are:

  • Default: Synchronize configuration for FortiAnalyzer, FortiSandbox, and Central Management to the root node.
  • Local: Do not synchronize configuration with the root node.

 

As mentioned, setting it to local will prevent the device from synchronizing the configuration with the root node.

 

Note: The 'set configuration-sync local' command is available only on a downstream FortiGate; in a root FortiGate, it is not available and therefore has been removed in FortiOS 7.6.1 and onwards.

 

To prevent logging on or enable logging only for the security events for the specific policies, freestyle log filters can be used:

see Technical Tip: Configuring advanced syslog free-style filters.

For information on how enabling 'set configuration-sync local' on a downstream device affects Security Fabric devices, see Technical Tip: The impact of 'set configuration-sync local' on the Security Fabric.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.