Created on
06-03-2025
12:35 AM
Edited on
08-17-2025
08:19 AM
By
Stephen_G
Description | This article describes the typical circumstances behind the 'Entry Change'. |
Scope | FortiAuthenticator. |
Solution |
Event ID 10002 refers to a log entry change event that was performed through the Graphical User Interface (GUI). This indicates that an admin-privileged user manually changed or edited a log entry using the system’s frontend interface, rather than via automated scripts or backend processes. The remote user sync rules would for be logged with ID 30303, for example.
The system event message(s) will look like the following:
date=2025-06-03 time=20:13:33+0000 oid=8888 logid=10002 cat="Event" subcat="Admin Configuration" level="information" nas="" action="Edit" status="" msg="Edited Remote SAML User: test@fortinet.net (changed fields: first name, last name, email address and display name)" user="admin"
date=2025-06-03 time=20:13:33+0000 oid=8888 logid=10002 cat="Event" subcat="Admin Configuration" level="information" nas="" action="Edit" status="" msg="Edited Remote LDAP User: test@fortinet.net (changed fields: first name, last name, email address and display name)" user="admin"
date=2025-06-03 time=20:13:33+0000 oid=8888 logid=10002 cat="Event" subcat="Admin Configuration" level="information" nas="" action="Edit" status="" msg="Edited Local User: test (changed fields: email address and Restrict GUI)" user="admin"
date=2025-06-03 time=20:13:33+0000 oid=8888 logid=10002 cat="Event" subcat="Admin Configuration" level="information" nas="" action="Edit" status="" msg="Edited Local User Profile: test (changed fields: country, mobile number, SMS gateway and email recovery)" user=""
date=2025-06-03 time=20:13:33+0000 oid=8888 logid=10002 cat="Event" subcat="Admin Configuration" level="information" nas="" action="Edit" status="" msg="Assigning FortiToken FTKXXXXXXXXXXXXX to local user profile test" user=""
date=2025-06-03 time=20:13:33+0000 oid=8888 logid=10002 cat="Event" subcat="Admin Configuration" level="information" nas="" action="Edit" status="" msg="Edited Setting: ha_hb_lost_threshold (changed fields: value)" user="admin" date=2025-06-03 time=20:13:33+0000 oid=8888 logid=10002 cat="Event" subcat="Admin Configuration" level="information" nas="" action="Edit" status="" msg="Edited Secondary Load Balancer : FAC (changed fields: name)" user="fortinetadmin" date=2025-06-03 time=20:13:33+0000 oid=8888 logid=10002 cat="Event" subcat="Admin Configuration" level="information" nas="" action="Edit" status="" msg="Edited HA Setting: ha_password (changed fields: value)" user="fortinetadmin"
There are many other different events, and they will still share the same event IDs under 10002. They can be viewed under Logging -> Log Access -> Logs -> Search, enter the event ID '10002'.
Related documentation: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.