Logging and Monitoring Flashcards
What are the three types of logs?
Traffic, events, Security logs
What do Traffic logs record?
traffic flow info, (http/https requests)
What are the three types of traffic logs?
Forward, Local, Sniffer
What is a forward log?
contains info about traffic FTG either accepted or rejected according to FW policy
What is a local log?
contains info about the traffic directly to and from the FG management IP add. Includes connection to the GUI and FortiGaurd queries.
What are sniffer logs
contain information related to traffic seen by the one-arm sniffer.
What are Event Logs?
Event logs record system and administrative events like adding or modifying a setting, or daemon activities or FortiGuard updates and GUI logins .
What are some examples of Event logs?
User, System, Router, VPN, Wifi
What are security logs?
record security events, such as virus attacks and intrusion attempts. They contain log entries based on the security profile type. (App Control, AV, DNS, File Filter, Web Filter, IP, SSL SSH)
What is the default number of days logs are stored on disk?
7 days
What is the highest severity of a log?
0 = Emergency (system is unstable)
What is the lowest severity of a log
7 Debug (rarely used unless working with Fortisupport)
If you are using one hard drive for WAN optimization can you use it for logging?
No, unless there is a second hard drive that is not being used for WAN optimization. If no second HD use syslog or FortiAnalyzer.
How much space does FTG reserve for logging?
Approx 75%
What are examples of Remote Logging Servers?
Syslog
FortiCloud
FortiAnalyzer
FortiSIEM
FortiManager