Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Frosty
Contributor

Syslog filters

Wondering if anyone happens to know which syslogd filter (e.g. config log syslogd2 filter, set <filter_name> enable) would control logs of type Event, sub-type System.  I can see these in my Fortianalyzer (LogView, Event, System), such as Login Success and Failure events.  I want to also push these events to a syslog server.

 

I couldn't find this info in online documentation or in the CLI manual, so have opened a ticket with support.

1 REPLY 1
Frosty
Contributor

Didn't really get anywhere with Support.

However I think I have an answer, namely that logs of type Event, System are NOT covered by the filters.  I've disabled all available filters and those events are coming through to my syslog server okay.

At least, I think so, am not 100% that there might not be some hidden CLI command somewhere that controls this.

Labels
Top Kudoed Authors