Wondering if anyone happens to know which syslogd filter (e.g. config log syslogd2 filter, set <filter_name> enable) would control logs of type Event, sub-type System. I can see these in my Fortianalyzer (LogView, Event, System), such as Login Success and Failure events. I want to also push these events to a syslog server.
I couldn't find this info in online documentation or in the CLI manual, so have opened a ticket with support.
Didn't really get anywhere with Support.
However I think I have an answer, namely that logs of type Event, System are NOT covered by the filters. I've disabled all available filters and those events are coming through to my syslog server okay.
At least, I think so, am not 100% that there might not be some hidden CLI command somewhere that controls this.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1114 | |
760 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.