FortiAppSec Cloud
FortiAppSec Cloud delivers unified application security and performance with WAF, bot protection, GSLB, DDoS mitigation, threat analytics, and CDN.
AACastillo
Staff
Staff
Article Id 392897
Description This article describes why it may not be possible to change the Log parameters like Log Format, Log Severity or Log Facility in the Export options to send logs to a remote location in FortiAppSec Cloud and how to solve it.
Scope FortiAppSec Cloud.
Solution

When a user has web applications in the WAF configuration of FortiAppSec Cloud, it is wanted to configure exporting attack logs to a log server by accessing Log Settings -> Attack Log Export -> Add Log Server. However, the Export Options may not be able to be changed:

 

001a.png

 

This is related to the user which access to FortiAppSec Cloud management, specifically with the IAM user read/write permissions for FortiAppSec Cloud settings. This can be checked by accessing FortiCloud with the master user account and then going to Services -> Assets & Accounts -> IAM:

 

002a.png

 

Select the IAM user that has access to FortiAppSec Cloud in Users:

 

003a.png

 

Check the FortiAppSec Cloud permissions in the configured Permission Profile and use for this user. Resource 'WAF - Settings' should be in 'Read & Write':

 

004a.png

 

To change this setting, go to Permission Profiles and choose the used Profile:

 

005a.png

 

Select 'Edit' to modify the permissions:

 

006a.png

 

Go to 'FortiAppSec Cloud' and in 'WAF - Settings' select 'Read & Write'. When it's ready, select 'Update.':

 

007a.png

 

Access again to FortiAppSec Cloud. All Log parameters (Log Format, Log Severity, and Log Facility) in Export options should be able to be changed:

 

008b.png

 

If the user has the 'WAF - Settings' permissions in 'Read & Write' and still cannot modify the Log parameters, open a TAC support ticket to check the situation.

Contributors