Skip to main content
Sathapon
New Member
April 7, 2020
Solved

Can I filter FortiGate's syslog setting

  • April 7, 2020
  • 2 replies
  • 4296 views

I have used the FortiGate for SSL-VPN only.  I would like the fortiGate send only log "User access Fortigate and User login SSL-VPN". to a syslog. What should I do? 

 

Details

FortiGate 101F

Firmware 6.2.3

    Best answer by jhouvenaghel_FTNT

    If you know the logid of these particular events then you should be able to  use  : 

    set filter "logid(id1,id2, ..)" with filter-type = include (under config log syslogd filter) 

    2 replies

    ede_pfau
    SuperUser
    SuperUser
    April 7, 2020

    IMHO, receive all event logs and filter on your syslog server.

    jhouvenaghel_FTNT
    Staff
    Staff
    April 7, 2020

    If you know the logid of these particular events then you should be able to  use  : 

    set filter "logid(id1,id2, ..)" with filter-type = include (under config log syslogd filter) 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!