Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Botnet and C&C logging
Hi there,
can anyone please tell me where to find logs regarding botnet and C&C?
Is it possible to send an mail for events regarding blocked botnet?
I did not find the answer in any documents.
Thanks in advance.
Best regards,
Thorsten
Solved! Go to Solution.
1 Solution
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just tested this now. It's logged under the AntiVirus section.
3 REPLIES 3
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi
Which fortios using?
You can block botnet & cc connection in application profile , av profile , dns filter profile and also in interface.
You have to enable logging to forticloud , log Disk or fortianalyzer to get the traffic event.
Forticloud will send a summary report on 24hr
Check the below Link to setup mail notifications
http://help.fortinet.com/...ring/Alert%20email.htm
Regards
Mahesh
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
I am using FortiOS 5.6.3
I would like to block botnet & cc connection directly at the interface.
Logging is enabled to disk.
Just wanted to see what is logged because of our data protection commissioner...
He is always aware of "protecting" our user rights ;)
Thanks,
Thorsten
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just tested this now. It's logged under the AntiVirus section.
