Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
HenryXu
New Contributor

FortiGate 400E extended logging

We deploy the FortiGate 400E as IDS to port mirror FortiGate FW.
- ips license is enable on this 400E, but without web filtering license.

To get http header raw data(request url, request method, user agent, x-forwarded-for,referer) from ips log.

Am I able to get http header data if just enable extended-log in ips profile setting ?

"set extended-log enable"

 

Thanks in advance.

Henry Xu

1 Solution
Debbie_FTNT
Staff
Staff

Dear Henry,

 

you should be able to get the HTTP headers in IPS logs just as well as webfilter logs - if you refer to https://docs.fortinet.com/document/fortigate/6.2.3/fortios-log-message-reference/630151/utm-extended... you can see that extended logging is for UTM logs in general, no matter the subtype (IPS, webfilter, whatever).

Please note that the full extended UTM log is only sent to reliable syslog servers (syslog via TCP), and all other logging solutions will receive a truncated rawdata field.

+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++

View solution in original post

2 REPLIES 2
Debbie_FTNT
Staff
Staff

Dear Henry,

 

you should be able to get the HTTP headers in IPS logs just as well as webfilter logs - if you refer to https://docs.fortinet.com/document/fortigate/6.2.3/fortios-log-message-reference/630151/utm-extended... you can see that extended logging is for UTM logs in general, no matter the subtype (IPS, webfilter, whatever).

Please note that the full extended UTM log is only sent to reliable syslog servers (syslog via TCP), and all other logging solutions will receive a truncated rawdata field.

+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++
HenryXu
New Contributor

Thanks Debbie for your quick response.

We've received the http headers in IPS logs.

The issue has been resolved.

Top Kudoed Authors