Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Sathapon
New Contributor

Can I filter FortiGate's syslog setting

I have used the FortiGate for SSL-VPN only.  I would like the fortiGate send only log "User access Fortigate and User login SSL-VPN". to a syslog. What should I do? 

 

Details

FortiGate 101F

Firmware 6.2.3

1 Solution
jhouvenaghel_FTNT

If you know the logid of these particular events then you should be able to  use  : 

set filter "logid(id1,id2, ..)" with filter-type = include (under config log syslogd filter) 

View solution in original post

2 REPLIES 2
ede_pfau
Esteemed Contributor III

IMHO, receive all event logs and filter on your syslog server.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
jhouvenaghel_FTNT

If you know the logid of these particular events then you should be able to  use  : 

set filter "logid(id1,id2, ..)" with filter-type = include (under config log syslogd filter) 

Labels
Top Kudoed Authors