Description | This article describes why Bandwidth usage of firewall policy shows higher in Syslog Server than in FortiGate. |
Scope | FortiGate. |
Solution |
In the below example, the total Bandwidth Usage in the firewall policy is 2.46 GB:
But on the Syslog server, it shows a higher value than what is shown on FortiGate. Reason: Generally syslog server calculates the cumulative value of rcvdbytes and sentbytes of all the log messages received. FortiGate sends interim logs which have rcvdbytes and sentbytes fields in the middle of a session. However, it calculates the usage properly by excluding the interim log entries and based on each session ID.
To stop interim logs, run the below commands:
config log syslogd filter |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.