Skip to main content
TomWhi
New Member
September 9, 2018
Question

Top Logging Policies

  • September 9, 2018
  • 1 reply
  • 8595 views

Hi,

 

My FortiAnalyser is creaking with too many logs being generated per day. We have "all logging" turned on a lot of policies which we can probably reduce to UTM logs only - but I'd like to have a report of which policies are creating the most amount of logs so I can target them first. 

 

Is there a report a a view I can enable to see which policies are generating the most amount of logs?

    1 reply

    emnoc
    New Member
    September 9, 2018

    What I would  do 

     

    1: if you have multiple  FGT logging  check the log per/sec per  fgt

    2:  Tackle the easy stuff ( do you log all dns lookup,  CIFS/SMB internal traffic, MS-AD traffic, etc...)'

    3: Do you log session start  

     

     

    I was in your shoes a year or two ago with a ORG that believed "log all" an everything was the smart ideal. Upper

    management and  CISO had no clue about what we logged and how to use and  effective logging solution.

     

    tanr
    New Member
    September 9, 2018

    If you don't have too many FortiGates or too many different security policies, you can just filter a days worth of logs by log UUID or log custom field and see how many you get for each policy.

     

    See http://socpuppet.blogspot.com/2017/06/fortios-logging-uuid.html for details on log UUID.

     

    See http://socpuppet.blogspot.com/2017/07/custom-log-fields-fortios.html for details on setting custom field for particular policies.

     

    I agree that a report from the FAZ for this sort of thing would be very useful, so if you come up with a solution please post it!  Quickest solution might be gotten by giving TAC a call.

    emnoc
    New Member
    September 9, 2018

    I agreed, look at the  top policies and  how many hits over a 1/2 day period during the week would be a start. Advise log with you need, and is useful.

     

    Ken