Description
This article describes how to test antivirus log generation on FortiGate.
Scope
FortiGate.
Solution
There may be cases where FortiGate generates no logs. In this case, ensure the FortiGate Antivirus signatures are working properly using the following method.
Use deep inspection in the internet-facing policy and ensure the certificate is installed on the user's machine.
Go to eicar's Malware testfile download page to generate antivirus traffic.
Go to the Download area using the secure, SSL-enabled protocol HTTPS and select eicar.com.
The AntiVirus block page should appear.
If there are no entries in the Antivirus logs, it indicates that the Antivirus has not detected any infected files. The command 'diagnose log test' can be used to generate a sample test log for all categories of logs, including AV logs.
Note:
On the Antivirus profile used on the respective firewall policy, the following entries must also be added:
config antivirus profile
edit <profile_name_of_av>
set av-virus-log enable <----- Enable/disable antivirus logging.
set av-block-log enable <----- Enable/disable logging for antivirus file blocking.
set extended-log enable <----- Enable/disable extended logging for antivirus.
next
end
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.