Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ZiPPy
New Contributor

Possible to log RDP connections?

We currently aren' t using VPN for a few users, and I was just curious if I can log the RDP sessions? I want to keep track of who is logging in to our system. I know RDP session' s isn' t the normal thing you would log, but I was hopping there was a way I could log them. In the Fortigate800 under Log&Report > Log Config > Log Config I don' t see where I could specify what to log. Any ideas?
5 REPLIES 5
ede_pfau
SuperUser
SuperUser

You can enable Traffic log and filter for destination port 3389 which is RDP. The minimum log level to see traffic logs is ' Information' .
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
ZiPPy
New Contributor

heya ede_pfau, So when you say enable Traffic log and set the filter for RDP, where exactly do you do this? To try and get this setup, I' ve configured the Syslog under Log Settings. The minimum severity level is Information, Facility: local7. I also have the interface ' log' option selected, so I' m starting to see some logs but of various types. So it' s the filter option you mentioned, I' m not quite sure where I would configure it.
ede_pfau
SuperUser
SuperUser

I meant local logging. ' Log & Report' > ' Log Setting' > ' Local Logging & Archiving' , check ' Memory' . Then scan the logs in ' Log Access' > ' Traffic' . Of course you can use the syslog as well. Filter the messages by ' type' (using findstr or grep or ...).
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
ZiPPy
New Contributor

I had to put this project on hold for awhile, but not returning to hopefully close it out. I' m still a little confused as to how to get these sessions logged. I didn' t see the ' Local Logging & Archiving' option, but under memory I' ve tried setting both Notification and Informational for the minimum severity level. I' m running version 3.00,build0479,070309 which as you can see is an older version. So under Log Access > I have the following options - Fortianalyzer, Memory, and Disk. I have the Log Type selected as Traffic Log. Am I missing something?
ZiPPy
New Contributor

Any thoughts gents?
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors