Hi all,
On my FGT, I activate message alert when admin login/logout.
Since I update FAZ to 6.0.0, I receive several time a day theses messages for each firewall.
Do you have same behaviour ?
Message meets Alert condition date=2018-05-02 time=02:45:54 devname=FGT60E-XXXXX devid=FGT60EXXXXXXX logid="0100032001" type="event" subtype="system" level="information" vd="root" eventtime=1525221954 logdesc="Admin login successful" sn="XXXXXXX" user="admin" ui="http(127.0.0.1)" method="http" srcip=127.0.0.1 dstip=127.0.0.1 action="login" status="success" reason="none" profile="super_admin" msg="Administrator admin logged in successfully from http(127.0.0.1)"
2 FGT 100D + FTK200
3 FGT 60E FAZ VM some FAP 210B/221C/223C/321C/421E
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I do have exactly the same behaviour.
Any explanations?
If you have security fabric enabled on the FortiGate, then FortiAnalyzer will try to login to the FortiGate to gather security fabric statistics & topology information.
For this to work properly you must setup a security fabric group in FortiAnalyzer which includes proper admin credentials in order for FortiAnalyzer to log into the FortiGate.
thanks for this explanation.
I follow this guide and it's working fine with only read access on system config.
But I still have a lot false positive : if I set Upload option to "reatime" :
Message meets Alert condition date=2018-06-07 time=15:27:00 devname=FGT60E-Xxx devid=FGT60E logid="0100032001" type="event" subtype="system" level="information" vd="root" eventtime=1528378020 logdesc="Admin login successful" sn=" xxx " user="faz-user" ui="http(127.0.0.1)" method="http" srcip=127.0.0.1 dstip=127.0.0.1 action="login" status="success" reason="none" profile="faz-user-group" msg="Administrator faz-user logged in successfully from http(127.0.0.1)" Message meets Alert condition date=2018-06-07 time=15:26:00 devname=FGT60E-Xxx devid=FGT60E logid="0100032001" type="event" subtype="system" level="information" vd="root" eventtime=1528377959 logdesc="Admin login successful" sn=" xxx " user="faz-user" ui="http(127.0.0.1)" method="http" srcip=127.0.0.1 dstip=127.0.0.1 action="login" status="success" reason="none" profile="faz-user-group" msg="Administrator faz-user logged in successfully from http(127.0.0.1)" Message meets Alert condition date=2018-06-07 time=15:25:00 devname=FGT60E-Xxx devid=FGT60E logid="0100032001" type="event" subtype="system" level="information" vd="root" eventtime=1528377899 logdesc="Admin login successful" sn=" xxx " user="faz-user" ui="http(127.0.0.1)" method="http" srcip=127.0.0.1 dstip=127.0.0.1 action="login" status="success" reason="none" profile="faz-user-group" msg="Administrator faz-user logged in successfully from http(127.0.0.1)" Message meets Alert condition date=2018-06-07 time=15:23:59 devname=FGT60E-Xxx devid=FGT60E logid="0100032001" type="event" subtype="system" level="information" vd="root" eventtime=1528377839 logdesc="Admin login successful" sn=" xxx " user="faz-user" ui="http(127.0.0.1)" method="http" srcip=127.0.0.1 dstip=127.0.0.1 action="login" status="success" reason="none" profile="faz-user-group" msg="Administrator faz-user logged in successfully from http(127.0.0.1)" Message meets Alert condition date=2018-06-07 time=15:22:59 devname=FGT60E-Xxx devid=FGT60E logid="0100032001" type="event" subtype="system" level="information" vd="root" eventtime=1528377779 logdesc="Admin login successful" sn=" xxx " user="faz-user" ui="http(127.0.0.1)" method="http" srcip=127.0.0.1 dstip=127.0.0.1 action="login" status="success" reason="none" profile="faz-user-group" msg="Administrator faz-user logged in successfully from http(127.0.0.1)" Message meets Alert condition date=2018-06-07 time=15:21:59 devname=FGT60E-Xxx devid=FGT60E logid="0100032001" type="event" subtype="system" level="information" vd="root" eventtime=1528377719 logdesc="Admin login successful" sn=" xxx " user="faz-user" ui="http(127.0.0.1)" method="http" srcip=127.0.0.1 dstip=127.0.0.1 action="login" status="success" reason="none" profile="faz-user-group" msg="Administrator faz-user logged in successfully from http(127.0.0.1)" Message meets Alert condition date=2018-06-07 time=15:21:29 devname=FGT60E-Xxx devid=FGT60E logid="0100032001" type="event" subtype="system" level="information" vd="root" eventtime=1528377689 logdesc="Admin login successful" sn=" xxx " user="faz-user" ui="http(127.0.0.1)" method="http" srcip=127.0.0.1 dstip=127.0.0.1 action="login" status="success" reason="none" profile="faz-user-group" msg="Administrator faz-user logged in successfully from http(127.0.0.1)" Message meets Alert condition date=2018-06-07 time=15:20:59 devname=FGT60E-Xxx devid=FGT60E logid="0100032001" type="event" subtype="system" level="information" vd="root" eventtime=xxx logdesc="Admin login successful" sn="xxx" user="faz-user" ui="http(127.0.0.1)" method="http" srcip=127.0.0.1 dstip=127.0.0.1 action="login" status="success" reason="none" profile="faz-user-group" msg="Administrator faz-user logged in successfully from http(127.0.0.1)" Message meets Alert condition date=2018-06-07 time=15:20:02 devname=FGT60E-Xxx devid=FGT60E logid="0100032001" type="event" subtype="system" level="information" vd="root" eventtime=xxx logdesc="Admin login successful" sn="xxx" user="faz-user" ui="http(127.0.0.1)" method="http" srcip=127.0.0.1 dstip=127.0.0.1 action="login" status="success" reason="none" profile="faz-user-group" msg="Administrator faz-user logged in successfully from http(127.0.0.1)"
I think Fortinet can find another way to get this working without this spam engine
2 FGT 100D + FTK200
3 FGT 60E FAZ VM some FAP 210B/221C/223C/321C/421E
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.