Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
CUB
New Contributor

VPN logs

I work on my Diploma, I am creating solution for analyze "raw" logs. In the present step I need to do identification login/logout/failed_login for this I need list of all records that can be in "msg" or "action" field, or any other marks of this actions in VPN session. Anybody can help me?

1 REPLY 1
AEK
SuperUser
SuperUser

 

ID: 39424
name: LOG_ID_EVENT_SSL_VPN_USER_TUNNEL_UP
action: tunnel-up
msg: SSL tunnel established
event: SSL VPN tunnel up
------------------------------------------------
ID 39947
Name LOG_ID_EVENT_SSL_VPN_SESSION_TUNNEL_UP
action: tunnel-up
msg: SSL tunnel established
event: SSL VPN tunnel up
------------------------------------------------
ID: 39426
name: LOG_ID_EVENT_SSL_VPN_USER_SSL_LOGIN_FAIL
action: ssl-login-fail
msg: SSL user failed to logged in
event: SSL VPN login fail
------------------------------------------------
ID: 39943
name: LOG_ID_EVENT_SSL_VPN_SESSION_NEW_CON
action: ssl-new-con
msg: SSL new connection
event: SSL VPN new connection
------------------------------------------------
ID 39948
name: LOG_ID_EVENT_SSL_VPN_SESSION_TUNNEL_DOWN
action: tunnel-down
SSL tunnel shutdown
event: SSL VPN tunnel down
------------------------------------------------
ID 39425
name: LOG_ID_EVENT_SSL_VPN_USER_TUNNEL_DOWN
action: tunnel-down
SSL tunnel shutdown
event: SSL VPN tunnel down


For full information:
https://docs.fortinet.com/document/fortigate/7.4.3/fortios-log-message-reference/39947/39947-log-id-...

 

Good luck for you diploma!

AEK
AEK
Labels
Top Kudoed Authors