Created on
07-25-2023
03:26 AM
Edited on
10-13-2025
10:33 PM
By
Anthony_E
| Description | This article describes how to exclude specific logs that have been sent to FortiAnalyzer. |
| Scope | FortiOS v7.0. |
| Solution |
There might be cases where a set of logs needs to be excluded by the FortiGate firewall from sending it to FortiAnalyzer.
The log storage on FortiAnalyzer is getting high, or false positive logs are triggering an action in FortiAnalyzer.
In the example below, a filter is configured to exclude specific log IDs:
config log fortianalyzer filter set filter-type exclude next end
Logs:
date=xxxx time=xxxx .. logid="0100026003" type="event" subtype="system" level="information" vd="root" logdesc="DHCP statistics" interface="xxx" total=3 used=0 msg="DHCP statistics" ...
LogID can be taken from the generated logs or from the document below:
26003 - LOG_ID_DHCP_STAT
Note: If FIPS-CC is enabled on the device, the command 'config free-style' will not be available.
Related document: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.