Skip to main content
sarathharidas99
New Member
November 29, 2018
Question

Logging Fortinet firewall configuration changes to ArcSight

  • November 29, 2018
  • 0 replies
  • 2753 views

Hi,

 

 I need help with the list of Fortigate system event ID’s for configuration changes. The event IDs should include all tasks as mentioned below:-

 

  • All actions taken by any individual with root or administrative privileges – includes updates and other system changes (not just rules)
  • Access to all audit trails
  • Invalid logical access attempts
  • Use of and changes to identification and authentication mechanisms—including but not limited to creation of new accounts and elevation of privileges—and all changes, additions, or deletions to accounts with root or administrative privileges
  • Initialization, stopping, or pausing of the audit logs
  • Creation and deletion of system-level objects[/ul]

    Please help with the same.