FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
pdelapena
Staff
Staff
Article Id 338434
Description This article describes how to export FortiGate logs (Forward Traffic, System Events, & etc.) in CSV/JSON format straight from the FortiGate.
Scope FortiOS v7.4+ and v7.6+
Solution

In FortiGate v7.4+ or v7.6+, it is possible to export logs in CSV/JSON format directly from the FortiGate itself.

 

It is important to take note first that there will be additional steps when the logs in the chosen log page are greater than 500 entries.

 

Condition 1 -- If logs are less than 500 entries :
Open the FortiGate GUI, go to 'Log & Report' and choose what log file to be exported. Hover to the top left part of the table and click the Gear button. The word 'Export' should be seen and choose what format to be downloaded, either 'CSV' or 'JSON' can be selected. File will automatically be downloaded in chosen (.csv or .json) format.

 

lessthan500.jpg

 

Condition 2 -- If logs are greater than 500 entries:
There is a prerequisite in order to generate a CSV/JSON file if logs are greater than 500 entries. The last log entry (can be seen in the bottom right part of the table) of the log page needs to be reached. If the prerequisite is not satisfied, there will be no file downloaded.

 

An indication that the bottom-most part of the log page is yet to be reached is when there is still "+" appended in the log number same as seen below. (For example: 500+, 1000+, 5000+, etc.)

 

500.jpg

 

There are two options that can be taken to satisfy the pre-requisites mentioned above :

  1. Scroll down in the log page until the last log entry has been reached. 


    2892.jpg

     

  2. If there are plenty of logs, first specify a time range in the log filter, then scroll down until the the last log entry has been reached. Once the pre-requisite has been satisfied, perform the same steps explained in Condition 1. There is an additional step in which the administrator will need to specify how many log entries to be downloaded out of the total number of logs. To finish, select the 'Export' button and the file will be downloaded.

Capture2.JPG

 

CSV-JSON-greaterthan500.JPG

 

Note: If there is additional information wanted in the generated CSV/JSON file, more options can be ticked in the Gear (Configure Table) button. 

Contributors