Skip to main content
ddsouza_FTNT
Staff
Staff
February 7, 2022

Technical Tip: How to collect the logs needed for investigating Bot Detection related issues

  • February 7, 2022
  • 0 replies
  • 842 views
Description This article describes steps to collect the logs needed for investigating Bot Detection related issues.
Scope For version 6.3 and above.
Solution

1) Debug output.

 

Open an SSH session to the Fortiweb and execute the following commands.

 

# diag deb reset
# diag deb timestamp enable
# diag debug flow filter http-detail 4
# diag deb flow filter flow-detail 4
# diag debug application bot-detection 7
# diag deb flow filter client-ip <client IP>
# diagnose debug flow filter server-ip <Virtual IP>
# diag debug info
# diag deb enable

 

2) Front end capture.

 

Login to GUI and go to System -> Network>Packet Capture, select interface as <VIP interface>', Host IP/Netmask as Client IP, port as <port used in the virtual server ->, maximum packet count 10000 and select 'Save', and then select Triangle button to Run.

 

ddsouza_FTNT_0-1644224404478.png

 

Note.

Make sure to define the Source NAT IP  as the client IP in both debug and capture if the client's IP address gets source NAT along the path.

 

3) Reproduce the problem.

 

Take a screenshot of the error seen on the client machine.

 

4) Stop the debug and capture.

 

After reproducing the problem, stop the debug and capture.

To stop the debug run the following commands.

 

# diag deb disable
# diag deb reset

 

5) Download the following files from the unit.


* Traffic logs.
* Event logs.
* Attack logs.
* Config file: go to System ->Backup & Restore, enable 'Include Machine Learning Data' and select Backup.

 ddsouza_FTNT_2-1644224628416.png

 

*  ML Bot detection .dat file: go to Policy -> Server Policy, edit the Server Policy in question -> Machine Learning -> Bot detection -> Export.

 ddsouza_FTNT_3-1644224790643.png

 

Attach all the files while raising the ticket so TAC can review them.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!