Is it possible to send only system events to syslog ?
According to documentation should be possible, haven't tried myself:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD40645 "Technical Note: Using Syslog Filters on FortiGate to send only specific logs to Syslog Server"
Yurihttps://yurisk.info/ blog: All things Fortinet, no ads.
Navigate to Log&Report>Log Settings> Event Logging > Choose customize and then system activity events.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2023 Fortinet, Inc. All Rights Reserved.