Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Simon
New Contributor II

No logs on Fortigate 30D - Firmware: FGT30D-5.00-build292

Hi

I have just setup a Fortigate 30D and configured it to use RSA SecurID 2FA which is working.

 

I have enabled event logging for all events. When I check the logs through the GUI and the Console they are all empty.

 

I have also enabled email alerting which is working.

 

any ideas?

Simon

 

 

2 Solutions
gschmitt
Valued Contributor

Logging has been disabled in later firmwares for smaller devices

 

Create a FortiCloud account and connect the device to it. You have 100MB logs per day for free and a total of 1GB Logs (Log size not traffic)

View solution in original post

Christopher_McMullan

If alert emails are working, then logging to some suitable non-memory destination is likely already set up, though maybe not for all events.

 

I would check on the default severity level of the events you want to record, and the log source the GUI looks at. Under Log & Report >Log Config > Log Settings, in the "GUI Preferences" section, what selection is chosen for "Display Logs From"?

 

And in the CLI:

config log <source> filter //--so, memory, disk, syslogd, etc., based on the Display Logs From setting above

get | grep severity

end

 

Memory logging, by default, uses 'warning' level severity, whereas most/all other destinations use 'information', which may account for the discrepancy between alert email events and the lack of logs when viewed locally on the FortiGate.

Regards, Chris McMullan Fortinet Ottawa

View solution in original post

2 REPLIES 2
gschmitt
Valued Contributor

Logging has been disabled in later firmwares for smaller devices

 

Create a FortiCloud account and connect the device to it. You have 100MB logs per day for free and a total of 1GB Logs (Log size not traffic)

Christopher_McMullan

If alert emails are working, then logging to some suitable non-memory destination is likely already set up, though maybe not for all events.

 

I would check on the default severity level of the events you want to record, and the log source the GUI looks at. Under Log & Report >Log Config > Log Settings, in the "GUI Preferences" section, what selection is chosen for "Display Logs From"?

 

And in the CLI:

config log <source> filter //--so, memory, disk, syslogd, etc., based on the Display Logs From setting above

get | grep severity

end

 

Memory logging, by default, uses 'warning' level severity, whereas most/all other destinations use 'information', which may account for the discrepancy between alert email events and the lack of logs when viewed locally on the FortiGate.

Regards, Chris McMullan Fortinet Ottawa

Labels
Top Kudoed Authors