Fortinet 543 FortiWeb 5.0 Patch 6 Administration Guide
About logs & loggingFortiWeb appliances can log many different network activities and traffic including:
• overall network traffic
• system-related events including system restarts and HA activity
• matches of policies with Action set to a log-generating option such as Alert
Each type can be useful during troubleshooting or forensic investigation. For more information
about log types, see “Log types” on page 543.
You can select a priority level that log messages must meet in order to be recorded. For more
information, see “Log severity levels” on page 544.
For a detailed description of each FortiWeb log message, as well as log message structure, see
the FortiWeb Log Message Reference.
The FortiWeb appliance can save log messages to its memory, or to a remote location such as a
Syslog server or FortiAnalyzer appliance. For more information, see “Configuring logging” on
page 545. The FortiWeb appliance can also use log messages as the basis for reports. For more
information, see “Reports” on page 586.
The FortiWeb appliance also displays event and attack log messages on the dashboard. For
more information, see “Attack Log Console widget” on page 536 and “Event Log Console
widget” on page 538.
See also
•Log types
•Log severity levels
•Configuring logging
•Viewing log messages
Log types
Each log message contains a Type ( type) field that indicates its category, and in which log file it
is stored.
FortiWeb appliances can record the following categories of log messages:
Table 48:Log types
Log type Description
Event Displays administrative events, such as downloading a backup copy of the
configuration, and hardware failure s.
Traf fic Displays traffic flow information, such as HTTP /HTTPS requests and
responses.
Attack Displays attack and intrusion attempt events.
Avoid recording highly frequent log types such as traffic logs to the local hard disk for an
extended period of time. Excessive logging frequency can cause undue wear on the hard disk
and may cause premature failure.