Hi there,
Is it normal that FortiOS doesn't log admin user creation events? I figured it was standard practice. I can't find anything regarding admin user events in the log reference. Thank you.
While I'm here, I actually have a few more questions about different logged events. For example, is there any reference to explain the difference between Log ID 00003 (Traffic violation - deny) and Log ID 00011 (Failed connection attempts)? To my understanding, these are quite similar. Does log ID 00011 only get logged for TCP syn packets and 00003 for any packet/port/protocol? Thank you!
No, logs will be generated when you create an admin account on the FortiGate. Refer to the link below.
Hi @superlativenickname,
Did you check under system event as well as change between log location such as memory and FortiGate Cloud?
User | Count |
---|---|
2259 | |
1225 | |
772 | |
451 | |
367 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.