Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Tempoary
New Contributor

Fortigate Log types

Hello everybody, I am making a list of the "recommended/important" fortigate log types for our customers. however i do not have access to a fortigate firewall and i cant seem to find any "good" documentation. so far what i have found has been contradicting itself by other searches.

 

so now i have taken to the community:) would anyone share what log types are available from the fortigate firewall and what those logs contain

6 REPLIES 6
AEK
SuperUser
SuperUser

Hi Temporary

Besides traffic log and local traffic log, here are the other available logs:

  • System activity event
  • VPN _activity event
  • User activity event
  • Router activity event
  • WiFi activity event
  • Explicit web proxy event
  • Endpoint event
  • HA event
  • Security Rating event
  • FortiExtender event
  • SDN connector Event
  • SD-WAN event
  • CIFS event
  • Switch controller event
AEK
AEK
Tempoary
New Contributor

Thank you AEK:)

Can you provide a brief explanation of what these contain:

CIFS event

SDN connector event

User activity (guessing its the same as traffic logs?)

switch controller event (guessing its changes to configs and alerts about switch ports?)

 

 

again thank you:)

GauravPandya
New Contributor III

Tempoary

Hi GauravPandya

yeah i have been looking at that documentation but from what i have read on other webpages/forums, the info appears to be outdated + when i ressarch what logtypes fortigate uses, other users respond with other logtypes that are not listed so its really confusing

GauravPandya

It depends on versions. URL which I have posted is from version 7.6. You can check admin guide based on your firewall version.

AEK
SuperUser
SuperUser

Here it is:

  • CIFS event: This one should be related to logs of CIFS protocol (Common Internet File System) file filtering, see "config cifs profile" if you are interested
  • SDN connector event: Logs related to public and private cloud solutions connectors
  • User activity: Logs related to user authentication, login, logout events
  • Switch controller event: Events that happening on the managed switches
AEK
AEK
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors