Created on
08-07-2023
10:31 PM
Edited on
08-07-2023
10:55 PM
By
Jean-Philippe_P
Description | This article describes how to read the FortiManager Event Logs for Address Group (device mapping modification). |
Scope | FortiManager. |
Solution |
In this example, it is necessary to configure as below:
Inside FortiManager Event Logs will record the firewall addresses and firewall address group information.
After downloading the FortiManager Event Logs (download in normal format), then it shows the below detail information. Note: It is possible to filter FortiManager Event Logs by description: cdb event log for object changed.
Information:
For device mapping inside the address group, the downloaded log information is shown below:
Now it is performed a modification inside this address group:
Inside FortiManager Event Logs will record the changes of firewall address group information. Download the FortiManager Event Logs in normal format for more detailed information.
After downloading the FortiManager Event Logs (download in normal format), then it is possible to see the below detailed information. Note: It is possible to filter FortiManager Event Logs by description: cdb event log for object changed.
The user admin has deleted the 'FGT_B' FortiGate device mapping from dummyGroup.
The user admin has removed a member (dummyIP_2) from the 'FGT_A' FortiGate device mapping from dummyGroup. The current member is only left dummyIP_1.
FortiManager Event Logs are important to trace back the modification on the address group (device mapping) so that it will get back the lost information. |