How do you guys handle the logging to fortianalyzer if you are in a zero trust environment? Do you log all traffic, do you log only security events, do you not log internal traffic but log external traffic? Also would logging security events only allow logging for DNS errors?
FAZ like SIEM recommends logging everything for better correlation.
DNS error are not necessarily security events. UTM logs are generated when the security profiles are violated, I mean DNS profile, Web filter, IPS, App ctrl and so.
| User | Count |
|---|---|
| 2926 | |
| 1456 | |
| 862 | |
| 826 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.