Hello!
I have a customer with a pair or 600E's that I'd like to configure to do heuristic scanning in monitor mode and check the logs.
The only helpful documentation that I can find is the following: https://kb.fortinet.com/kb/documentLink.do?externalID=FD48939
If I had a smaller model, then I'm assuming I could just do:
# config antivirus heuristic set mode pass
But since I have a 600E, do I need to also configure the "set drop_heuristic" and/or the "set store_heuristic" commands? I'm not quite sure what the purpose of these commands are for - especially if I don't want to do any quarantining.
Finally, I'd like to see the results of any heuristic scans. Would I search for virus="unknown" in the syslog output? Can anyone confirm? Or is there another way to see what the results of what the heuristic scans caught?
I appreciate any input on the subject!
Ok, after opening a case w/ FortiNet, I got my answers:
[ol]Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1741 | |
1109 | |
755 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.