Skip to main content
ZiPPy
New Member
March 14, 2012
Question

Possible to log RDP connections?

  • March 14, 2012
  • 5 replies
  • 7971 views
We currently aren' t using VPN for a few users, and I was just curious if I can log the RDP sessions? I want to keep track of who is logging in to our system. I know RDP session' s isn' t the normal thing you would log, but I was hopping there was a way I could log them. In the Fortigate800 under Log&Report > Log Config > Log Config I don' t see where I could specify what to log. Any ideas?

    5 replies

    ede_pfau
    SuperUser
    SuperUser
    March 15, 2012
    You can enable Traffic log and filter for destination port 3389 which is RDP. The minimum log level to see traffic logs is ' Information' .
    ZiPPy
    ZiPPyAuthor
    New Member
    March 15, 2012
    heya ede_pfau, So when you say enable Traffic log and set the filter for RDP, where exactly do you do this? To try and get this setup, I' ve configured the Syslog under Log Settings. The minimum severity level is Information, Facility: local7. I also have the interface ' log' option selected, so I' m starting to see some logs but of various types. So it' s the filter option you mentioned, I' m not quite sure where I would configure it.
    ede_pfau
    SuperUser
    SuperUser
    March 16, 2012
    I meant local logging. ' Log & Report' > ' Log Setting' > ' Local Logging & Archiving' , check ' Memory' . Then scan the logs in ' Log Access' > ' Traffic' . Of course you can use the syslog as well. Filter the messages by ' type' (using findstr or grep or ...).
    ZiPPy
    ZiPPyAuthor
    New Member
    August 20, 2012
    I had to put this project on hold for awhile, but not returning to hopefully close it out. I' m still a little confused as to how to get these sessions logged. I didn' t see the ' Local Logging & Archiving' option, but under memory I' ve tried setting both Notification and Informational for the minimum severity level. I' m running version 3.00,build0479,070309 which as you can see is an older version. So under Log Access > I have the following options - Fortianalyzer, Memory, and Disk. I have the Log Type selected as Traffic Log. Am I missing something?
    ZiPPy
    ZiPPyAuthor
    New Member
    August 28, 2012
    Any thoughts gents?
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!