Being new to the FortiGates, I probably have a misunderstanding on the log settings within the firewall policy. In the FortiManager, we have certain lines set to "Log All Sessions" that we are particular interested in, with the majority set to either "Log Violation Traffic" (for blocks) or "Log Security Events", and it's set this way with the intent of somewhat restricting logs that are being sent to our SIEM. We have to pay for extra log data, so we'd like to trim out what isn't needed.
After troubleshooting today, I believe this affects what's presented in the Log & Report > Forward Traffic. There were no results for a lline configured with "Log Security Events", but there was after this was changed to "Log All Sessions."
Is it typical practice to set every line in the Firewall Policy to "Log All Sessions." I understand there is a logging level configured in the syslog configuration, but does the logging level in the firewall policy affect what goes out via syslog?
Thank you.
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Created on 03-24-2023 12:03 PM Edited on 03-24-2023 12:04 PM
If I'm not mistaken, only for local traffic/logs or sent to FortiAnalyzer.
Syslog has it's own settings in regards to facility.
"Log security events" will only show up traffic log match UTM profile defined.
"Log all sessions" will include traffic log include both match and non-match UTM profile defined.
Is this only for the local logs on the FortiGate or does it include syslog or both?
Created on 03-24-2023 12:03 PM Edited on 03-24-2023 12:04 PM
If I'm not mistaken, only for local traffic/logs or sent to FortiAnalyzer.
Syslog has it's own settings in regards to facility.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.