Logs and reports overview
The FortiDDoS system supports the logging and reporting features you expect in a security appliance:
- Local logging
- Remote logging (syslog and SNMP traps)
- FortiAnalyzer and FortiSIEM support (syslog only)
- SNMP (MIB Queires, Alarm and Attack Log Traps)
- Email Alerts (SMTP alerts for selected admin Events)
- SQL Query support (expert only with support of development team)
- Real-time system status and traffic monitoring
- Configurable system event and security event logging
- Filtering of log tables
- Customizable, scheduled and Threshold-based reports, with multiple formats and delivery options
The table below details the remote logging and services available in the system as well as where they are configured:
Event | Remote Logging | Settings |
---|---|---|
CPU, Memory, Disk Capacity Alarms | SNMP Traps | System > SNMP > System Information / Config |
Event Logs | Syslog messages | Log & Report > Log Configuration > Event Log Remote |
Alert Email Messages (Selected Events) | Log & Report > Log Configuration > Alert Email Settings | |
Attack Logs | SNMP Traps | Log & Report > Log Configuration > SNMP Trap Receivers |
Syslog messages | Log & Report > Log Configuration > DDoS Attack Log Remote |
System Data | Remote Queries | Settings |
---|---|---|
Traffic Data and other info | SNMP MIB Queries | System > SNMP > System Information / Config |