Created on 08-07-2024 10:29 PM Edited on 08-07-2024 10:29 PM By Anthony_E
This article describes how to use Teraterm to generate long term log files.
FortiAP, Teraterm version 4.
Sometimes, TAC needs to monitor for extended periods, running a series of diagnostic commands every certain amount of time to get device status until certain conditions occur before a problem can be detected.
Generating a single SSH log file will be difficult as it may fail due to the diagnostic computer resources (RAM, storage) being exhausted before gathering any useful information. In this case, generating an automatic log file every few megabytes can prevent this issue and generate log files with an appropriate size for easier analysis and sharing with other teams, also it will control and free up RAM usage on diagnose computer.
Follow the steps below:
Set log rotation enabled with size 10 Mbytes and rotation set to 0.
Note:
Test these settings first by configuring a small file size like 100k and check if the settings are correct. Then change to the intended file size.
Under the Logging Options submenu, set log options Append, Plain Text, and enable timestamp with local time.
As an example, a script for a FortiAP has been developed, ap-ext-mon.ttl, to make it easier to run a script on the FortiAP.
It will disable the admin timeout timer, show the current status on FortiAP, and clear old kernel panic records, then start to run in an endless loop with some commands to monitor. It will end when the ssh session is disconnected or when user manually stops it. It will open second window to control script execution.
Use this script as an example to create custom scripts.
Look at the Wifi event logs and filter by FortiAP NAME or Serial to know about the time the problem has happened. If monitoring another device, it is also possible to use the device log to find relevant events and then use the date and time on log entries to find relevant log files.
Upload to Ticket the first generated file from both sessions and files generated around the time the problem was registered and export Filtered FortiAp WIFI event logs to a file and attach it for analysis.
Note:
Share the first generated files with TAC in advance to check if everything is set up properly before you start logging, it could be useful to make sure all requested information is generated.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.