Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
badrgb
New Contributor III

FortiAnalyzer Logs (Status field)

Hello,

 

I have a question for the expert. 

 

I can see in my logs one log with close in the statuts no start no accept before just one entry. It is normal?

In my head a connexion need to start then closed!!? Am I wrong?

any explination please.

 

Thank you

1 REPLY 1
badrgb
New Contributor III

Hello,

 

I found an explanation for not have a log with "Start" value, it's when a rule is created, if the field « generate logs when session starts » is checked we can have those logs if not we can't.

 

Anyone have an idea or explanation about "accept" and "close" status? it's mandatory to have both of them? an "accept" then a "close" or not?

Labels
Top Kudoed Authors