We deploy the FortiGate 400E as IDS to port mirror FortiGate FW.
- ips license is enable on this 400E, but without web filtering license.
To get http header raw data(request url, request method, user agent, x-forwarded-for,referer) from ips log.
Am I able to get http header data if just enable extended-log in ips profile setting ?
"set extended-log enable"
Thanks in advance.
Henry Xu
Solved! Go to Solution.
Dear Henry,
you should be able to get the HTTP headers in IPS logs just as well as webfilter logs - if you refer to https://docs.fortinet.com/document/fortigate/6.2.3/fortios-log-message-reference/630151/utm-extended... you can see that extended logging is for UTM logs in general, no matter the subtype (IPS, webfilter, whatever).
Please note that the full extended UTM log is only sent to reliable syslog servers (syslog via TCP), and all other logging solutions will receive a truncated rawdata field.
Dear Henry,
you should be able to get the HTTP headers in IPS logs just as well as webfilter logs - if you refer to https://docs.fortinet.com/document/fortigate/6.2.3/fortios-log-message-reference/630151/utm-extended... you can see that extended logging is for UTM logs in general, no matter the subtype (IPS, webfilter, whatever).
Please note that the full extended UTM log is only sent to reliable syslog servers (syslog via TCP), and all other logging solutions will receive a truncated rawdata field.
Thanks Debbie for your quick response.
We've received the http headers in IPS logs.
The issue has been resolved.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1741 | |
1109 | |
755 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.