Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
oden007
New Contributor

How to get logs out of Fortigate firewalls?

Hi, we just bought a pair of Fortigate 100f and 200f firewalls. However, even despite configuring a syslog server to send stuff to, it sends nothing worthwhile.

Things I’d like to see: Failed logon attempts, #, ip address, username

Any action taken by IPS to ban/timeout said IPs

Portscans done on our public facing IPs

Any malicious attacks detected that are sent our way

I thought this would be easy to do but haven’t been successful figuring out where to configure any of it. Is this possible on Fortigates?

https://showbox.bio https://vidmate.cool/
1 REPLY 1
gfleming
Staff
Staff

Absolutely possible! However you'll have a heck of a time doing what you want by just sending to syslog server.

 

Highly suggest you look at logging to FortiCloud or FortiAnalyzer (you can run a free trial VM). You will get much more out of it that way.

Cheers,
Graham
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors