Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
IPS Event Log
Hi there,
Is there a way to log the threats detected by the IPS (not the packets).
I can' t see anything IPS related on my " UTM Security Log" .
Thanks.
3 REPLIES 3
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Ricdgr,
Please give more detailed about the problem, i.e topology, configuration.
Thanks,
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is there a way to log the threats detected by the IPS (not the packets). I can' t see anything IPS related on my " UTM Security Log" .I believe IPS events show up in the attack log, which should be enabled by default when you enable sql-logging.
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0
(FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes you can log events in the log. You need to enable this under your ips sensor
set
action action of selected rules
log logging of selected rules
IIRC the default action is to log.
PCNSE
NSE
StrongSwan
PCNSE
NSE
StrongSwan
