Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ismailurek2
New Contributor III

FortiGate 7.2.9 security events summary logs not showing

Hello,

 

Securtiy Events Summary logs do not appear on FortiGate. FortiGate version 7.2.9. Does anyone have a solution for this?

1 Solution
ismailurek2

Hi,

 

Enabling the Historical FortiView option solved the problem. The disk information started to appear in the upper right corner and we could see the logs in the summary area.

 

Regards

View solution in original post

9 REPLIES 9
dingjerry_FTNT

Hi @ismailurek2 , 

 

Have you enabled the logging setting in any firewall policy? If yes, can you confirm if there is any traffic hitting this policy?

Regards,

Jerry
ismailurek2

Hi 

 

It is allowed through Policy. In fact, it is seen when you enter the details of security events logs. Our problem is that nothing is seen in the security events summary field.

I have policies with security profile applied and it generates logs but it does not appear in the security events summary field.

 

The necessary permissions are also turned on in the log settings field.

 
 

image.png

 

ismailurek2

This is actually the case. I need to figure out what's causing this problem.image.png

dingjerry_FTNT

Hi @ismailurek2 ,

 

Your first screenshot shows Disk Logging enabled. The second screenshot shows you are looking for logs with FortiAnalyzer as the source.

 

I am not sure whether you have enabled sending logs to FAZ or not.  If not, please switch to Disk as source on the top-right corner in your second screenshot.

Regards,

Jerry
ismailurek2

Hi @dingjerry_FTNT ,

 

Only FortiAnalyzer is visible in the top right corner. Although disk logging is enabled, I cannot see the disk in that section. Fortinet TAC also suggested me to select a disk there, but only FortiAnalyzer is visible. By the way, we also send logs to FortiAnalyzer.

image.png

Regards,

dingjerry_FTNT

Do you have any relevant Forward Traffic logs there?

Regards,

Jerry
ismailurek2

Yes we have any Forward Traffic logs.

dingjerry_FTNT

Hi @ismailurek2 ,

 

1) Please share the relevant firewall policy configurations:

 

show firewall policy <ID>

 

2) Download one relevant traffic log in raw format for the said firewall policy

Regards,

Jerry
ismailurek2

Hi,

 

Enabling the Historical FortiView option solved the problem. The disk information started to appear in the upper right corner and we could see the logs in the summary area.

 

Regards

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors