Skip to main content
alex_d
New Member
September 12, 2019
Question

Log traffic options for IPv4 Policy

  • September 12, 2019
  • 2 replies
  • 3030 views

Hi everybody,

I'm new in the FortiWorld, and I need to understand the exact difference between "Log Security Events" and "Log All Sessions" when I configure an IPv4 policy via FortiManager.

I would also like to understand the impact this choice will have on my infrastructure. (storage, ...)

I looked (a lot) in the documentation available at Fortinet, but I didn't find this information.

Thank in advance for your help.

2 replies

Dave_Hall
New Member
September 12, 2019

Log Security Events will only log Security (UTM) events (e.g. AV, IPS, firewall webfilter), providing you have applied one of them to a firewall (rule) policy.  Log all traffic will do just that - personally, I would not enabled "Log all traffic" unless I need to troubleshoot something in near real time.

alex_d
alex_dAuthor
New Member
September 13, 2019

First of all, thanks a lot for this quick answer. Just to be sure I understand correctly the difference, could you give me some examples of information that I will find by activating "Log All Sessions" and that I wouldn't find with "Log Security Events" (even if I add the "Generate Logs when Session Starts" option) for a specific IPv4 policy rule ?

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.