Skip to main content
Frosty
New Member
March 15, 2017
Question

Syslog filters

  • March 15, 2017
  • 1 reply
  • 4196 views

Wondering if anyone happens to know which syslogd filter (e.g. config log syslogd2 filter, set <filter_name> enable) would control logs of type Event, sub-type System.  I can see these in my Fortianalyzer (LogView, Event, System), such as Login Success and Failure events.  I want to also push these events to a syslog server.

 

I couldn't find this info in online documentation or in the CLI manual, so have opened a ticket with support.

    1 reply

    Frosty
    FrostyAuthor
    New Member
    April 4, 2017

    Didn't really get anywhere with Support.

    However I think I have an answer, namely that logs of type Event, System are NOT covered by the filters.  I've disabled all available filters and those events are coming through to my syslog server okay.

    At least, I think so, am not 100% that there might not be some hidden CLI command somewhere that controls this.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!