Hi there,
Hoping someone has the magic sauce to fix my problem.
Our main firewall is FG200B running v5.0.10 and is very stable.
We have a Fortianalyzer 100C and have been using that okay for several years.
Recently a Juniper JSA appliance has been introduced to our network.
I want to send syslog(514) messages from the FG200B to the Juniper JSA.
Have used "conf log syslogd ..." to set up the syslog definition.
Have been able to successfully forward general traffic logs and so on to the Juniper.
What I really want to do: turn OFF all logging to the Juniper EXCEPT for Administrative type events.
e.g. when an administrator logs on to or off from the Fortigate
e.g. when the configuration of the Fortigate is modified
All the detailed logging I am happy to just leave running through the Fortianalyzer.
Can someone point me to the specific "set *something* enable" in "conf log syslogd filter" which will do just this?
Thanks!
Steve
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.