Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
happyling111
New Contributor II

Can syslog collect notifications of setting changes?

Hello all,


Can Fortigate syslog receive routing or VPN "configuration change" notifications?

I know that syslog can receive status change notifications, and change notifications can be sent via email alerts, but I don't know if syslog can receive them.

I've checked, and I don't seem to have seen any instructions for this.

1 Solution
happyling111
New Contributor II

6 REPLIES 6
smaruvala
Staff
Staff

Hi,

 

- Configuration changes can be seen in the events logs in the Firewall. Please refer the below link.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-check-filter-configuration-changes-...

 

- If we put filter of "Object attribute configured" as log description we will see configuration changes. 

- I am not very clear about the second part of your issue. Is the requirement is to send only these logs to syslog from fortigate?

 

Regards,

Shiva

happyling111

Is the requirement is to send only these logs to syslog from fortigate?
yes!

smaruvala

Hi,

 

- Then you can use filters in the syslog setting in the firewall to do that.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Using-syslog-filters-on-to-send-only-speci...

- You can see Log ID in the details of the event logs. You can filter and send only the specific log ID. for Example log ID 44547 will be used for object attribute changed in the Firewall.

 

Regards,

Shiva

happyling111
New Contributor II

Hello,

After testing, the command within the provided link is functional in version 6.0.l6.
However, with OS 7.0.12, the command in the link is not applicable.
Could you please provide the correct command for filtering logid in this version?

Tks!

happyling111
New Contributor II

smaruvala
Staff
Staff

Hi,

 

Please check the 7.0 document.

https://docs.fortinet.com/document/fortigate/7.0.4/cli-reference/450620/config-log-syslogd-filter

Sample:

config free-style
edit 1
set category event
set filter "(logid 0100044547)"
next
end

 

Regards,

Shiva

Labels
Top Kudoed Authors