12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Log&Report<br />

Configuring FortiGuard Analysis Service<br />

Logging to a FortiGuard Analysis server<br />

You can configure logging to a FortiGuard Analysis server after registering your<br />

account. It is re<strong>com</strong>mended to ensure the connection between your <strong>FortiGate</strong> unit<br />

and FortiGuard Analysis server is working properly before configuring logging.<br />

You can enable logging of <strong>FortiGate</strong> features from the <strong>FortiGate</strong> web-based<br />

manager. See “Log types” on page 481 for more information. Traffic and full<br />

content archiving will be supported in future releases.<br />

To configure logging to a FortiGuard Analysis server<br />

1 Log into the web-based manager of the <strong>FortiGate</strong> unit you want registered.<br />

1 Go to Log&Report > Log Config.<br />

2 Select the FortiGuard Analysis Service checkbox.<br />

3 Select the blue arrow to expand the FortiGuard Analysis Service options.<br />

4 Select one of the following:<br />

overwrite<br />

Do not log<br />

Select to delete the oldest log entry and continue logging when the<br />

maximum log disk space is reached.<br />

Select to stop log message going to the FortiGuard Analysis<br />

server when the maximum log disk space is reached.<br />

5 Select a log severity level.<br />

6 Select Apply.<br />

Accessing logs on the FortiGuard Analysis server<br />

The FortiGuard Analysis server provides both real-time and historical views of log<br />

messages. Real-time logs display log information and updates continually,<br />

providing recent updates and events occurring on the <strong>FortiGate</strong> unit. Historical<br />

logs display log information for a selected device and log type for a specific time<br />

range.<br />

To access real-time logs<br />

1 Log into the portal.<br />

2 Go to Log > Log Viewer > Real-time.<br />

3 Select a device in Devices.<br />

4 Select a log type in Log types.<br />

5 Select OK.<br />

If you want to change what log type you are currently viewing, select change, next<br />

to the Type name. You can also stop real-time logs by selecting Stop. When you<br />

want to start real-time logs again, select Start. The option Start only displays when<br />

you have selected Stop.<br />

To access historical logs<br />

1 Log into the portal.<br />

2 Go to Log > Log Viewer > Historical.<br />

3 Select the Historical tab.<br />

4 Select a device in Devices.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 479

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!