Skip to main content
avp
Staff
Staff
June 18, 2025

Technical Tip: Explaining FortiGate update related log IDs

  • June 18, 2025
  • 0 replies
  • 3935 views
Description This article describes how FortiGate update-related logs are identified with log IDs.
Scope FortiGate.
Solution

Whenever an update succeeds or fails in FortiGate, it generates certain system event logs. It can be filtered by the Message, Log Description, or Log IDs as follows:

 

  1. If the FortiGate update succeeds: 
    • Log Description: 'FortiGate update succeeded'.
    • Log ID: '0100041000'.

 

LOG success.png

 

date=2025-06-18 time=13:13:13 eventtime=1750232592215806964 tz="+0530" logid="0100041000" type="event" subtype="system" level="notice" vd="root" logdesc="FortiGate update succeeded" status="update" msg="Fortigate scheduled update fcni=yes fdni=yes fsci=yes from 173.243.141.6:443"

 

  1. If the FortiGate update fails:
    • Log Description: 'FortiGate update failed'.
    • Log ID: '0100041001'.

 

log failed.png

 

date=2025-06-18 time=13:16:43 eventtime=1750232803487756713 tz="+0530" logid="0100041001" type="event" subtype="system" level="critical" vd="root" logdesc="FortiGate update failed" status="update" msg="Fortigate update now failed"

 

If the scheduled update causes temporary interruption or outage, it can be disabled under System -> FortiGuard -> FortiGuard Update by toggling the 'Scheduled update' option. 


To disable the FortiGuard update from the CLI, run the following:

 

config system autoupdate schedule
    set status disable
end

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!