FortiSandbox
FortiSandbox provides a solution to protect against advanced threats and ransomware for companies who don’t want to implement and maintain a sandbox environment on their own.
ojacinto
Staff
Staff
Article Id 257485
Description This article describes how to see logs and scan results for On-demand/API submission.
Scope

FortiSandbox and VMs, version 3.2.4, 4.0.0 and above, version 4.2.0 and above.

Solution

Currently, the diagnose-debug option is available for the Device/Adapter.
There is no option to debug for API/On-demand submitted files.


diagnose-debug -h

 

Usage: diagnose-debug [netshare|device|adapter] [device_serial_number]
netshare: Network share daemon
device: OFTP daemon for FGT/FML/FCT devices.
adapter_cb: Daemon for third party appliance Bit9 + CARBON BLACK
adapter_icap: Daemon for Internet Content Adaptation Protocol (ICAP)
adapter_bcc: Daemon for BCC
adapter_mta_relay: Daemon for MTA Relay
adapter_mta_mail: Daemon for MTA Mail

However, it is possible to see the logs and scan results for On-demand/API submission in the following way:

 

1) Go to Log & Report -> Local Log ->  Enabled Log Level
By default, only the following log levels are enabled: Alert, Critical, Error, Warning and Information.

 

2) Select also the option 'Debug Logs' and select 'Save'.

 

Debug_log.jpg

 

3) Now go to Scan Input -> File On-Demand and perform and submit the file.
Then go to Log & Report -> All Events and now, the logs about the submitting, fetching, processing, and scanning result will be visible for the file:

 

debug1.jpg

 

 

Contributors