Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
woytass
New Contributor

No IPS logs on Syslog server

Hi, I' ve already setup Splunk and syslog server, so Fortigate is sending logs to Splunk. Splunk receiving almost all logs except IPS. My CLI settings are:
 FGT80 # config log syslogd filter 
 FGT80 (filter) # get
 severity            : notification 
 forward-traffic     : enable 
 local-traffic       : enable 
 multicast-traffic   : enable 
 sniffer-traffic     : enable 
 anomaly             : enable 
 netscan-discovery   : enable 
 netscan-vulnerability: enable 
 voip                : enable 
  
 
I have some IPS logs in Fortigate web console. What could i miss?
1 REPLY 1
norouzi
Contributor

Did you enable IPS Sensor in your policy?

If yes, check logging of your IPS Sensor like:

 

config ips sensor

edit default (IPS Sensor NAME)

config entries

edit 1

get

 

output is something like this:

id : 1 action : default application : all location : all log : enable log-packet : disable os : all protocol : all quarantine : none rule: severity : high critic status : default tags:

 

 

As you see, logging must be enable. If is not enable it.

 

 

 

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors