Skip to main content
JohnGeorge
New Member
June 9, 2016
Question

Fortigate and Syslog Question

  • June 9, 2016
  • 1 reply
  • 3956 views

-Fortigate 300D

-Firmware 5.2.6 build 711

 

Logs are being sent to a Syslog server, and appear to be Information severity/priority level. This is way too much logging. I would like to drop this down to Notification or Warning level. In the GUI or CLI, I don't see a way to adjust the level, only enable/disable "Endpoint Event," "Router Activity Event, "VPN Activity event" and so on for the VDOMs.  How can the logging level for Syslogs on the Fortigate be adjusted, or is it a matter of filtering what gets logged at the Syslog server?

    1 reply

    Jeff_FTNT
    Staff
    Staff
    June 9, 2016

    You may go to CLI :

    config  log  syslogd filter   FG200B3910600188 (filter) # get severity            : information forward-traffic     : enable local-traffic       : enable multicast-traffic   : enable sniffer-traffic     : enable anomaly             : enable netscan-discovery   : enable netscan-vulnerability: enable voip                : enable

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!