Hi,
I want to create a report of the rules and objects created/deleted on the firewall. As far as I can see, there is no such report in the default. When I say manual for Fortigate, it does not send a distinctive log (such as policy created) Has anyone experienced this?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi adem_netsys,
The according log (via syslog) gets the event type "FortiGate-event-config-object-attribute-message". The Firewall Action will be "Add"/"Delete", the Object Path will describe the distinct change, in your case probably "firewall.policy". In the "User defined msg", there will be the full description of the change on which you can filter, if you like.
So, for auditing, you will need to build a report based on this information manually.
Best,
Christian
Hi @Secusaurus,
Thank you for your reply. Well, how will this situation be for Palo Alto because it may be necessary to explain this correctly to the customer.
Hi adem_netsys,
Unfortunately, I do not have a Palo Alto FW in our lab for looking up these logs. I would expect these logs to be found somewhere here:
Best,
Christian
Thank you all of them
Not a topic here, but you may have come across it. I am getting esx logs and observing the device status in Siem. I have previously taken the logs that came to the supervisor to the collector and rediscovered them, but after that the device information started to return empty (memory, cpu, etc.), what could be the cause?
I know FortiAnalyzer can parse this, if it can, perhaps you could try sending this information to SIEM via a separate event each time a user disconnects?
Hi, not sure I follow this last question. What logs are you trying to parser?
Welcome to your new Fortinet Community!
You'll find your previous forum posts under "Forums"
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.