Skip to main content
Frosty
New Member
March 22, 2016
Question

How can I forward just Administrative/Config Change type events only to SYSLOGD

  • March 22, 2016
  • 0 replies
  • 2631 views

Hi there,

Hoping someone has the magic sauce to fix my problem.

Our main firewall is FG200B running v5.0.10 and is very stable.

We have a Fortianalyzer 100C and have been using that okay for several years.

Recently a Juniper JSA appliance has been introduced to our network.

I want to send syslog(514) messages from the FG200B to the Juniper JSA.

Have used "conf log syslogd ..." to set up the syslog definition.

Have been able to successfully forward general traffic logs and so on to the Juniper.

What I really want to do:  turn OFF all logging to the Juniper EXCEPT for Administrative type events.

e.g. when an administrator logs on to or off from the Fortigate

e.g. when the configuration of the Fortigate is modified

All the detailed logging I am happy to just leave running through the Fortianalyzer.

Can someone point me to the specific "set *something* enable" in "conf log syslogd filter" which will do just this?

Thanks!

Steve

    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!