Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Test85
New Contributor

Botnet and C&C logging

Hi there,

 

can anyone please tell me where to find logs regarding botnet and C&C?

Is it possible to send an mail for events regarding blocked botnet?

 

I did not find the answer in any documents.

 

Thanks in advance.

 

Best regards,

Thorsten

1 Solution
neonbit
Valued Contributor

Just tested this now. It's logged under the AntiVirus section.

View solution in original post

3 REPLIES 3
mahesh_secure
Contributor

Hi Which fortios using? You can block botnet & cc connection in application profile , av profile , dns filter profile and also in interface. You have to enable logging to forticloud , log Disk or fortianalyzer to get the traffic event. Forticloud will send a summary report on 24hr Check the below Link to setup mail notifications http://help.fortinet.com/...ring/Alert%20email.htm Regards Mahesh
Test85

Hi,

 

I am using FortiOS 5.6.3

 

I would like to block botnet & cc connection directly at the interface.

Logging is enabled to disk.

 

Just wanted to see what is logged because of our data protection commissioner...

He is always aware of "protecting" our user rights ;)

 

Thanks,

Thorsten

neonbit
Valued Contributor

Just tested this now. It's logged under the AntiVirus section.

Labels
Top Kudoed Authors