Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
badrgb
New Contributor III

FortiAnalyzer Logs (Status field)

Hello,

 

I have a question for the expert. 

 

I can see in my logs one log with close in the statuts no start no accept before just one entry. It is normal?

In my head a connexion need to start then closed!!? Am I wrong?

any explination please.

 

Thank you

1 REPLY 1
badrgb
New Contributor III

Hello,

 

I found an explanation for not have a log with "Start" value, it's when a rule is created, if the field « generate logs when session starts » is checked we can have those logs if not we can't.

 

Anyone have an idea or explanation about "accept" and "close" status? it's mandatory to have both of them? an "accept" then a "close" or not?

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors