Hello,
Please, how I can keep the traffic logs allowed by all the access list, and send just a logs of SOME rules to the FortiAnalyzer ?
to better explain:
for exemple: keep on the fortigate disk the trafic log of the rules id: 1 and 2 and 3, and send only the traffic log of the rule id 3 to the fortianalyzer.
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
If enable " Av/Web filter/Application control/IPS, etc on policy, it will have log for security event, it is call "Security log"
Local traffic mean traffic terminate or initiate from FGT, like if you login FGT with GUI/Telnet/SSH. Thanks.
Log filter is based on log type, can not based on policy.
FG800C3912800675 # config log fortianalyzer filter FG800C3912800675 (filter) # get severity : information forward-traffic : enable local-traffic : enable multicast-traffic : enable sniffer-traffic : enable
...
Your scenario can not reach, thanks.
thanks for the reply.
I want to know please, the logging option "security log" what does it mean exactly?.
last question: what kind of traffic can we found on "local traffic" ?
thanks again for your help.
If enable " Av/Web filter/Application control/IPS, etc on policy, it will have log for security event, it is call "Security log"
Local traffic mean traffic terminate or initiate from FGT, like if you login FGT with GUI/Telnet/SSH. Thanks.
thanks a lot
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.