Skip to main content
Abdal_opr
New Member
January 24, 2025
Question

Disable Logging for specific Policy Rules for device in Security Fabric

  • January 24, 2025
  • 3 replies
  • 1553 views

FG-Version: 7.2.10

 

Hi Community,

 

I’m looking for help on how to disable logging for specific policy rules in Fortigate devices that are part of a security fabric. I’ve tried changing the rules, but it hasn't worked.

 

Has anyone figured this out? Any advice would be really appreciated!

 

Thanks!

3 replies

AEK
SuperUser
SuperUser
January 26, 2025

Hi Abdal

This command will let you customize the logging of each policy.

config system csf
set configuration-sync local
end

But please check this tech tip for more details and for the impact.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-The-impact-of-set-configuration-sync-local-on-the/ta-p/360538

Hope it helps.

AEK
Abdal_opr
Abdal_oprAuthor
New Member
January 27, 2025

Thank you, but I would like to configure this on the root firewall. Is this possible, and would it have any negative impacts in this case?

 

Thank you for your response.

AEK
SuperUser
SuperUser
January 27, 2025

I already tested it and I found no impact on the traffic or on anything else related to the production.

However I know that the default is to log all traffic logs because with FortiAnalyzer (or other equipment like SIEM) it is recommended to send all logs without exception in order to do a better correlation and analysis.

AEK
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.