- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Event log when modify, crete, add or delete administration user
Hello team,
On Firewall FGT, When a user with administrative privileges is added\modified\removed on a Fortigate firewall is there a specific event that we find in the logs? Or is it something that needs to be manually enabled?
Thanks in advance
BR
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It is log ID 0100044547 for both adding and deleting in General System Events and enabled by default:
- Add system.admin
- Delete system.admin
Log ID | 0100044547 |
Type | event |
Sub Type | system |
If you have found a solution, please like and accept it to make it easily accessible for others.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
System event log is generated. You can find it by navigating GUI: Log & Report - Events - System events and search for string in the message "system."
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It is log ID 0100044547 for both adding and deleting in General System Events and enabled by default:
- Add system.admin
- Delete system.admin
Log ID | 0100044547 |
Type | event |
Sub Type | system |
If you have found a solution, please like and accept it to make it easily accessible for others.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is this log ID still accurate as of 08/2024?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Those usually don't change, have you tested it and not getting the same log ID?
From a quick search it appears also in FortiOS 7.6.
If you have found a solution, please like and accept it to make it easily accessible for others.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm searching in FortiAnalyzer for add/delete events but when I look for this log id, I am getting different event types that are not related. I am searching across a time range where I know add changes were made (I was the one that added an account) but nothing relevant is coming up (I am seeing firewall policy edit events).
