Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Frosty
Contributor

Real Time logging on FG200B + Fortianalyzer 100C

I'm trying to get my head around a slightly confusing observation.  We have an FG200B running v5.0.9 paired with an FL100C also now running v5.0.9 firmware.

 

Back in June 2014 we updated our FG200B from v4.3.15 to v5.0.7 firmware.  As part of that upgrade, I changed our logging setup on the FG200B to "real time" logging.  My recollection is that this was recommended before upgrading to v5.0.7

 

I've noticed since that date that SOME of the log file types stopped being created under Log View on the FL100C unit as of the date that the FG200B switched to Real Time logging:  Application Control (rlog), Attack (alog), Virus (vlog), Data Leak Prevention (dlog), Email Filter (slog) and Web Filter (wlog)

 

But other log files are still getting created and appear under Log View on the FL100C:  Event (elog), VOIP (plog), Network Scan (nlog) and Traffic (tlog)

 

Just wondering why this is inconsistent?  The FL100C is correctly receiving log data for categories such as Application Control, Web Filter and so on ... its just a bit confusing that there are no corresponding log files for these, whereas with Event and Traffic logs there are log files being created.  Just seems odd!

1 REPLY 1
Frosty
Contributor

I now have an answer to this, after having logged a ticket with Fortinet.

Nothing to do with "real time logging".  Everything to do with the v5.0 upgrade.

It seems that the "missing" log files are meant to be missing.

Those log entries are now being stored on the FL100C in the Traffic log files.

Apparently the data can be viewed by setting the appropriate Filter on the log data view, as per this response from Fortinet:

 

"All UTM log are written into tlog file. That is just a storage change.

 snip...

 To see UTM log in tlog, just display tlog in log browse, then apply search/filter on type or subtype, like: 1. type=utm, search all utm log; 2. subtype=virus/webfilter/dlp/ips/app-ctrl ... etc"

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors