FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
dferiadelgado
Article Id 383083
Description

This article describes how to locate logs that detail the creation of a system administrator user, including information on who acted.

Scope FortiGate.
Solution

Details about who created a system administrator user and when it was created can be obtained by reviewing the logs under System Events. It enables the Administrator to identify the creator of a specific user and the corresponding date.

 

To locate the logs associated with the event, navigate to Logs & Report -> System Events.

 

dferiadelgado_3-1742348857760.png

 

A log filter must be applied due to the high volume of logs being saved daily. To create the filter, navigate to the 'Logs' add a new filter, select the 'Message' column, and enter 'add system.admin'.

 

dferiadelgado_4-1742348857763.png

 

 

In this way, the administrator will be able to identify the exact date and the user who created the new system administrator account.

 

dferiadelgado_5-1742348857765.png

 

The system event can also be viewed by searching with logid: 44547:

 

image (20).png

 

To know who creates a local user instead of a system administrator refer to this article: Technical Tip: How to review user creation logs to determine who created it

Comments
MaryBolano
Staff
Staff

Great job @dferiadelgado Keep it up!