Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Frosty
Contributor

How can I forward just Administrative/Config Change type events only to SYSLOGD

Hi there,

Hoping someone has the magic sauce to fix my problem.

Our main firewall is FG200B running v5.0.10 and is very stable.

We have a Fortianalyzer 100C and have been using that okay for several years.

Recently a Juniper JSA appliance has been introduced to our network.

I want to send syslog(514) messages from the FG200B to the Juniper JSA.

Have used "conf log syslogd ..." to set up the syslog definition.

Have been able to successfully forward general traffic logs and so on to the Juniper.

What I really want to do:  turn OFF all logging to the Juniper EXCEPT for Administrative type events.

e.g. when an administrator logs on to or off from the Fortigate

e.g. when the configuration of the Fortigate is modified

All the detailed logging I am happy to just leave running through the Fortianalyzer.

Can someone point me to the specific "set *something* enable" in "conf log syslogd filter" which will do just this?

Thanks!

Steve

0 REPLIES 0
Labels
Top Kudoed Authors