Skip to main content
faizanshaikh_net
New Member
October 27, 2016
Question

Policy UUID - Logs & Reports

  • October 27, 2016
  • 8 replies
  • 14509 views

Friends,

 

Why is it that I see policy UUID in some of the logs while it is absent in others?

8 replies

emnoc
New Member
October 27, 2016

You can  enable  UUID logging  or lack of. It's very help if you are tacking items by UUID. I use it a lot btw.

 

global options

 

 

set log-uuid policy-only

 

Ken

 

 

 

faizanshaikh_net
New Member
October 27, 2016

Hi Ken,

 

Actually, I could see some unusual logs in my Logs & Reports section. There is a policy which is disabled for logging completely, yet I see that there are huge logs generated through it. I am assuming that these logs are junk. When I right click the policy after enabling it, and select "matching logs" I can only see the logs with UUID associated to them.

 

I am pretty new to Fortigates :)

emnoc
New Member
October 27, 2016

There is a policy which is disabled for logging completely, yet I see that there are huge logs generated through it.

 

 

Explain? How could that be?

 

If you have logging enable for  category traffic, &  traffic that matches that fwpolicy , you will send a log  message. If you have UUID enable for policy,  the log message is tagged with the  UUID. There's no way you can have it disable and still see logging imho & I don't know what you mean by "junk logs".

 

 

Login thru ssh or jsconsole  and find  the firrewallpolicy and look for the log traffic set command? What is it set for?

 

 

example

 

  show full firewall  policy 7 | grep log

        set logtraffic all

        set logtraffic-start disable

 

 

Ken

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!