Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
aunghtunoo
New Contributor

Cannot view real time log in fortigate 200D OS version 5.0

Hi Anyone ,

 

Pls advice me how to fix following issue

 

Issue

- All logs are stopped since December but Unit is working like normal except this issue.

 

My Setting

- I configured logs to store in local disk of fortigate.

- Time zone is point to Local time zone ( not NTP ).

 

Many Thanks

Max

 

 

 

 

 

3 REPLIES 3
neonbit
Valued Contributor

Few things you could double check:

1. Confirm disk logging is enabled:

fortigate # get log disk setting | grep status status              : enable

2. Confirm logs will be displayed from disk:

fortigate#   get log gui-display | grep location location             :  disk

3. Confirm if the log disk is available:

fortigate # get sys status | grep Log Log hard disk: Available

4. Run a log test to populate all logs:

fortigate # diagnose log test generating a system event message with level - warning generating an infected virus message with level - warning generating a blocked virus message with level - warning generating a URL block message with level - warning generating a DLP message with level - warning generating an IPS log message generating an anomaly log message generating an application control IM message with level - information generating an IPv6 application control IM message with level - information generating deep application control logs with level - information generating an antispam message with level - notification generating an allowed traffic message with level - notice generating a multicast traffic message with level - notice generating a ipv6 traffic message with level - notice generating a wanopt traffic log message with level - notification generating a HA event message with level - warning generating netscan log messages with level - notice generating a VOIP event message with level - information generating a DNS event message with level - information generating authentication event messages generating a Forticlient message with level - information generating a URL block message with level - warning

5. Log out of the GUI and back in. 

 

Hopefully you should now see some logs.

aunghtunoo

Thanks Neonbit !

 

But show nothing when I type as following

 

2. Confirm logs will be displayed from disk:

fortigate#get log gui-display | grep location  (note: no accept this syntax in forti OS verion 5.0.2) 3. Confirm if the log disk is available:

fortigate # get sys status | grep Log (note: syntax is accept by unit but show nothing )

 

Issue is still cannot fix now so pls help any idea .

Thanks so much

neonbit
Valued Contributor

Hello,

 

For 5.0.2 please try the following:

2. Confirm logs will be displayed from disk:

FortiGate-VM64 # config log setting FortiGate-VM64 (setting) # get | grep gui gui-location        : disk 3.Confirm if the log disk is available:

 

Type in get system status and look for something about Log hard disk as highlighted below:

 

FortiGate-VM64 # get system status Version: FortiGate-VM64 v5.0,build0271,140124 (GA Patch 6) Virus-DB: 16.00560(2012-10-19 08:31) Extended DB: 1.00000(2012-10-17 15:46) IPS-DB: 4.00345(2013-05-23 00:39) IPS-ETDB: 0.00000(2001-01-01 00:00) Serial-Number: FGVMEV0000000000 Botnet DB: 1.00000(2012-05-28 22:51) License Status: Valid Evaluation License Expires: Wed Jan 27 16:15:55 2016 VM Resources: 1 CPU/1 allowed, 976 MB RAM/1024 MB allowed BIOS version: 04000002 Log hard disk: Available Hostname: FortiGate-VM64 Operation Mode: NAT

Labels
Top Kudoed Authors