Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
luca1994
New Contributor III

Event log when modify, crete, add or delete administration user

Hello team,

 

On Firewall FGT, When a user with administrative privileges is added\modified\removed on a Fortigate firewall is there a specific event that we find in the logs? Or is it something that needs to be manually enabled?

 

Thanks in advance

BR

1 Solution
ebilcari
Staff
Staff

It is log ID 0100044547 for both adding and deleting in General System Events and enabled by default:

Add system.admin

Delete system.admin

Log ID 0100044547
Type event
Sub Type system

 

logid.PNG

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.

View solution in original post

2 REPLIES 2
abarushka
Staff
Staff

Hello,

 

System event log is generated. You can find it by navigating GUI: Log & Report - Events - System events and search for string in the message "system."

FortiGate
ebilcari
Staff
Staff

It is log ID 0100044547 for both adding and deleting in General System Events and enabled by default:

Add system.admin

Delete system.admin

Log ID 0100044547
Type event
Sub Type system

 

logid.PNG

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors