Created on
12-21-2025
08:07 AM
Edited on
12-29-2025
08:07 AM
By
Stephen_G
| Description | This article describes how to configure subnet-based syslog filtering on FortiGate devices, allowing users to filter traffic logs based on specific source or destination IP addresses. |
| Scope | FortiGate. |
| Solution |
To configure subnet-based syslog filtering on FortiGate, follow the steps below:
config log syslogd setting
Configure the subnet-based filter using CLI:
Capturing syslog traffic on the firewall shows that only logs matching the configured filters are forwarded to the syslog server:
Once the logs are forwarded to the syslog server, the source or destination IP addresses can be verified to confirm that the received logs match the filters configured on the firewall:
Free-style expression can be configured as follows:
Enter a free-style expression. For example:
Note: To forward a specific subnet of IP addresses, the entire network range of IP addresses should be defined in the filter.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.