Skip to main content
Giovanna
Explorer II
July 4, 2025
Solved

Fortigate Anomaly Logs

  • July 4, 2025
  • 1 reply
  • 719 views

Hi, I would like to ask if to generate logs of type "Anomaly" like for example 18432 - LOGID_ATTCK_ANOMALY_TCP_UDP, a fortiguard IPS license is needed for fortigate?

Best answer by Yurisk

Specifically for this log the license is not needed, but ... this log can be generated by either IPS or DDOS protection. DDOS protection does not require nor license nor subscription and would generate such log. The IPS, on the other hand w/o license will not function at all (2 years ago it would work but w/o signature updates from FortiGuard) and accordingly will not generate such log. 

1 reply

Yurisk
SuperUser
YuriskAnswer
SuperUser
July 4, 2025

Specifically for this log the license is not needed, but ... this log can be generated by either IPS or DDOS protection. DDOS protection does not require nor license nor subscription and would generate such log. The IPS, on the other hand w/o license will not function at all (2 years ago it would work but w/o signature updates from FortiGuard) and accordingly will not generate such log.