User ManualTable of ContentsTable of Contents3Introduction7Operational Modes8Active Mode8Passive Mode9About this guide10FortiLog documentation10Related documentation11FortiGate documentation11FortiManager documentation12FortiClient documentation12FortiMail documentation12Fortinet Knowledge Center12Comments on Fortinet technical documentation12Customer service and technical support13Setting up the FortiLog unit15Checking the package contents15Hardware specifications16Dimensions16Weight16Power requirements17Environmental specifications17Air flow17Mechanical loading17Planning the installation17Connecting the FortiLog unit18Configuring the FortiLog unit19Using the web-based manager19Using the command line interface20Using the front panel buttons and LCD21Connecting to the FortiLog Unit23Sending device logs to the FortiLog unit23Configuring FortiGate unit running FortiOS 2.823Configuring FortiGate devices running FortiOS 2.524Configuring FortiMail devices25Configuring the FortiLog unit26Adding a device26Defining device port interfaces27Creating Device Groups28Managing the FortiLog unit29Status29Status29Changing the FortiLog host name31Changing operating modes31Viewing system resources information32Changing the firmware32Installing firmware from a system reboot33Testing a new firmware image35Installing a backup firmware image36Switching to a backup firmware image38Switching to the default firmware image38Backing up system settings39Downlading the FortiLog debug log39Restoring system settings40Restore factory default system settings40Restoring a FortiLog unit40RAID41Config42Network42RAID43Log settings44Log policy45Time46Options46Admin46Configure Administrator access47Administrator account levels48Administrator options48Changing the Administrator password49Devices (Active mode)49Device list50Adding and registering a device50Editing device information50Alert Email51Server51Local52Device (Active mode)52Creating a new device alert52Alerts54Network Sharing55Defining IP aliases55Reports57Creating and generating a report57Configuring report parameters58Configuring a report query59Creating a query profile60Selecting the devices for the report60Creating a device profile61Select filtering options61Creating a filter profile62Setting a report schedule62Creating a report schedule profile63Choosing the report destination and format63Creating a report destination and format profile64Reports on demand64Viewing reports65Roll up report66Individual reports66Vulnerability reports67Creating and generating a report67Selecting report result parameters68Selecting plug-ins68Creating a plug-in profile69Selecting the scan targets for the report69Creating a scan target profile70Choosing the report destination and format71Creating a report destination and format profile71Viewing the vulnerability report72Using Logs73The Log view interface74Viewing logs74Finding log information75Importing log files77Log Search78Log watch (Active mode)78Event correlation (Active mode)79Using the FortiLog unit as a NAS81Connecting to the FortiLog file system81Providing access to the FortiLog hard disk82Selecting a file sharing protocol82Adding and modifying user accounts82Adding and modifying group accounts83Assigning access to folders83Modifying the user or group folder access85Setting folder and file properties86FortiLog CLI reference87CLI documentation conventions87Connecting to the CLI88Connecting to the FortiLog-800 console88Setting administrative access for SSH or Telnet89Connecting to the FortiLog CLI using SSH90Connecting to the FortiLog CLI using Telnet90CLI commands91execute branch91get branch92set branch94set alertemail94set console97set log98set NAS103set report104set system104unset branch110Appendix A: Log Report Types113Network Activity113Web Activity113FTP Activity114Terminal Activity115Mail Activity115Intrusion Activity116Antivirus Activity116Web Filter Activity116Mail Filter Activity117VPN Activity118Content Activity118Index121Size: 2.28 MBPages: 124Language: EnglishOpen manual