Description
This article describes how to test antivirus log generation on FortiGate.
Scope
FortiGate.
Solution
There may be cases where FortiGate generates no logs. In this case, ensure the FortiGate Antivirus signatures are working properly using the following method.
Use deep inspection in the internet-facing policy and ensure the certificate is installed on the user's machine.
Go to the following website to generate antivirus traffic: https://www.eicar.org/download-anti-malware-testfile/.
Go to the Download area using the secure, SSL-enabled protocol HTTPS and select eicar.com.
The AntiVirus block page should appear.
Note:
On the Antivirus profile used on the respective firewall policy, the following entries must also be added:
config antivirus profile
edit <profile_name_of_av>
set av-virus-log enable
set av-block-log enable
set extended-log enable
next
end
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.