Logging and Monitoring Flashcards
What are the three types of logs?
Traffic, events, Security logs
What do Traffic logs record?
traffic flow info, (http/https requests)
What are the three types of traffic logs?
Forward, Local, Sniffer
What is a forward log?
contains info about traffic FTG either accepted or rejected according to FW policy
What is a local log?
contains info about the traffic directly to and from the FG management IP add. Includes connection to the GUI and FortiGaurd queries.
What are sniffer logs
contain information related to traffic seen by the one-arm sniffer.
What are Event Logs?
Event logs record system and administrative events like adding or modifying a setting, or daemon activities or FortiGuard updates and GUI logins .
What are some examples of Event logs?
User, System, Router, VPN, Wifi
What are security logs?
record security events, such as virus attacks and intrusion attempts. They contain log entries based on the security profile type. (App Control, AV, DNS, File Filter, Web Filter, IP, SSL SSH)
What is the default number of days logs are stored on disk?
7 days
What is the highest severity of a log?
0 = Emergency (system is unstable)
What is the lowest severity of a log
7 Debug (rarely used unless working with Fortisupport)
If you are using one hard drive for WAN optimization can you use it for logging?
No, unless there is a second hard drive that is not being used for WAN optimization. If no second HD use syslog or FortiAnalyzer.
How much space does FTG reserve for logging?
Approx 75%
What are examples of Remote Logging Servers?
Syslog
FortiCloud
FortiAnalyzer
FortiSIEM
FortiManager
What are the differences between FortiManager and FortiAnalyzer from a logging perspective?
FortiManager limits logs volumes are limited to a fixed amount per day
Whereas FortiAnalyzer is meant to store and analyze logs so its limit is much higher.
What process caches logs with FTG can’t reach FrotiAnalyzer?
miglogd (for long enough to reboot FortiAnalyzer)
What port does FTG use for log transmission?
UDP 514
What compression algorithm is used to compress logs
LZ4
In a Firewall policy What does Logging allowed traffic setting do?
It needs to be turned on for any logging to occur
In a Firewall policy What does only logging security events provide?
logs appear in the forward traffic log and security log.
In a Firewall policy What does logging All sessions provide?
Every session generates a log and is logs appear in the security log events
How do you anonymize logs of usernames?
config log setting
Set user-anonymize enable
How do you view logs associated with a FW policy?
Right click on the policy and then click Show Matching Logs
Your customer has configured FTG to send logs to FortiAnalyzer but the test connectivity button continues to show a failed connection. What’s wrong?
You need to register FTG to the FortiAnalyzer.