Description | This article describes the typical circumstances behind the 'Entry Addition'. |
Scope | FortiAuthenticator. |
Solution |
Event ID 10001 refers to a log entry addition event that was performed through the Graphical User Interface (GUI). This indicates that an admin-privileged user manually created or submitted a log entry using the system’s frontend interface, rather than via automated scripts or backend processes. This log does not capture any subsequent actions such as editing or removing entries. It serves as a record of user-initiated "add" actions for auditing and traceability.
The sample system event message(s) will look like below:
date=2025-04-14 time=20:13:33+0000 oid=8888 logid=10001 cat="Event" subcat="Admin Configuration" level="information" nas="" action="Add" status="" msg="Added Remote LDAP User: test" user="admin"
date=2025-04-14 time=20:13:33+0000 oid=8888 logid=10001 cat="Event" subcat="Admin Configuration" level="information" nas="" action="Add" status="" msg="Added LDAP Server: test-LDAP (fortinet.net)" user="admin"
date=2025-04-14 time=20:13:33+0000 oid=8888 logid=10001 cat="Event" subcat="Admin Configuration" level="information" nas="" action="Add" status="" msg="Added Remote SAML User: no-reply@fortinet.net" user="admin"
date=2025-04-14 time=20:13:33+0000 oid=8888 logid=10001 cat="Event" subcat="Admin Configuration" level="information" nas="" action="Add" status="" msg="Added SAML IdP Active Session: no-reply@fortinet.net" user=""
date=2025-04-14 time=20:13:33+0000 oid=8888 logid=10001 cat="Event" subcat="Admin Configuration" level="information" nas="" action="Add" status="" msg="Added Guest User: testtest" user="admin"
date=2025-04-14 time=20:13:33+0000 oid=8888 logid=10001 cat="Event" subcat="Admin Configuration" level="information" nas="" action="Add" status="" msg="Added Certificate Enrollment Request: C=DE, CN=fortinet" user=""
date=2025-04-14 time=20:13:33+0000 oid=8888 logid=10001 cat="Event" subcat="Admin Configuration" level="information" nas="" action="Add" status="" msg="Added User Certificate: User_Cert_32 [C=DE, CN=userpki]" user=""
date=2025-04-14 time=20:13:33+0000 oid=8888 logid=10001 cat="Event" subcat="Admin Configuration" level="information" nas="" action="Add" status="" msg="Added Local User Profile: testprofile" user=""
date=2025-04-14 time=20:13:33+0000 oid=8888 logid=10001 cat="Event" subcat="Admin Configuration" level="information" nas="" action="Add" status="" msg="Added Local User: test" user=""
date=2025-04-14 time=20:13:33+0000 oid=8888 logid=10001 cat="Event" subcat="Admin Configuration" level="information" nas="" action="Add" status="" msg="Added User RADIUS Attribute: Fortinet-Group-Name (SSLVPNGroup)" user="admin"
date=2025-04-14 time=20:13:33+0000 oid=8888 logid=10001 cat="Event" subcat="Admin Configuration" level="information" nas="" action="Add" status="" msg="Added FortiToken: FTK200XXXXXXXXXX" user="admin"
date=2025-04-14 time=20:13:33+0000 oid=8888 logid=10001 cat="Event" subcat="Admin Configuration" level="information" nas="" action="Add" status="" msg="Added Static Route: 192.168.1.0/24 via 10.10.10.1 (port2)" user="admin"
date=2025-04-14 time=20:13:33+0000 oid=8888 logid=10001 cat="Event" subcat="Admin Configuration" level="information" nas="" action="Add" status="" msg="Added Setting: ha_monitor_ifaces" user="admin"
date=2025-04-14 time=20:13:33+0000 oid=8888 logid=10001 cat="Event" subcat="Admin Configuration" level="information" nas="" action="Add" status="" msg="Added Remote TACACS+ User: test" user="admin"
date=2025-04-14 time=20:13:33+0000 oid=8888 logid=10001 cat="Event" subcat="Admin Configuration" level="information" nas="" action="Add" status="" msg="Added User Widget: 'User Inventory' widget for user 'test'" user="admin"
There are many other different events, and they will still share the same event IDs under 10001. They can be viewed under Log Access -> Logs -> filter '10001'. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.