Fortinet black logo

CLI Reference

log disk filter

Configure filters for local disk logging. Use these filters to determine the log messages to record according to severity and type.

  config log disk filter
      Description: Configure filters for local disk logging. Use these filters to determine the log messages to record according to severity and type.
      set severity [emergency|alert|...]
      set forward-traffic [enable|disable]
      set local-traffic [enable|disable]
      set multicast-traffic [enable|disable]
      set sniffer-traffic [enable|disable]
      set anomaly [enable|disable]
      set voip [enable|disable]
      set dlp-archive [enable|disable]
      set gtp [enable|disable]
      set event [enable|disable]
      set system [enable|disable]
      set radius [enable|disable]
      set ipsec [enable|disable]
      set dhcp [enable|disable]
      set ppp [enable|disable]
      set admin [enable|disable]
      set ha [enable|disable]
      set auth [enable|disable]
      set pattern [enable|disable]
      set sslvpn-log-auth [enable|disable]
      set sslvpn-log-adm [enable|disable]
      set sslvpn-log-session [enable|disable]
      set vip-ssl [enable|disable]
      set ldb-monitor [enable|disable]
      set wan-opt [enable|disable]
      set wireless-activity [enable|disable]
      set cpu-memory-usage [enable|disable]
      set filter {string}
      set filter-type [include|exclude]
  end

config log disk filter

Parameter Name Description Type Size
severity Log to disk every message above and including this severity level.
emergency: Emergency level.
alert: Alert level.
critical: Critical level.
error: Error level.
warning: Warning level.
notification: Notification level.
information: Information level.
debug: Debug level.
option -
forward-traffic Enable/disable forward traffic logging.
enable: Enable forward traffic logging.
disable: Disable forward traffic logging.
option -
local-traffic Enable/disable local in or out traffic logging.
enable: Enable local in or out traffic logging.
disable: Disable local in or out traffic logging.
option -
multicast-traffic Enable/disable multicast traffic logging.
enable: Enable multicast traffic logging.
disable: Disable multicast traffic logging.
option -
sniffer-traffic Enable/disable sniffer traffic logging.
enable: Enable sniffer traffic logging.
disable: Disable sniffer traffic logging.
option -
anomaly Enable/disable anomaly logging.
enable: Enable anomaly logging.
disable: Disable anomaly logging.
option -
voip Enable/disable VoIP logging.
enable: Enable VoIP logging.
disable: Disable VoIP logging.
option -
dlp-archive Enable/disable DLP archive logging.
enable: Enable DLP archive logging.
disable: Disable DLP archive logging.
option -
gtp Enable/disable GTP messages logging.
enable: Enable GTP messages logging.
disable: Disable GTP messages logging.
option -
event Enable/disable event logging.
enable: Enable setting.
disable: Disable setting.
option -
system Enable/disable system activity logging.
enable: Enable system activity logging.
disable: Disable system activity logging.
option -
radius Enable/disable RADIUS messages logging.
enable: Enable RADIUS messages logging.
disable: Disable RADIUS messages logging.
option -
ipsec Enable/disable IPsec negotiation messages logging.
enable: Enable IPsec negotiation messages logging.
disable: Disable IPsec negotiation messages logging.
option -
dhcp Enable/disable DHCP service messages logging.
enable: Enable DHCP service messages logging.
disable: Disable DHCP service messages logging.
option -
ppp Enable/disable L2TP/PPTP/PPPoE logging.
enable: Enable L2TP/PPTP/PPPoE logging.
disable: Disable L2TP/PPTP/PPPoE logging.
option -
admin Enable/disable admin login/logout logging.
enable: Enable admin login/logout logging.
disable: Disable admin login/logout logging.
option -
ha Enable/disable HA logging.
enable: Enable HA logging.
disable: Disable HA logging.
option -
auth Enable/disable firewall authentication logging.
enable: Enable firewall authentication logging.
disable: Disable firewall authentication logging.
option -
pattern Enable/disable pattern update logging.
enable: Enable pattern update logging.
disable: Disable pattern update logging.
option -
sslvpn-log-auth Enable/disable SSL user authentication logging.
enable: Enable SSL user authentication logging.
disable: Disable SSL user authentication logging.
option -
sslvpn-log-adm Enable/disable SSL administrator login logging.
enable: Enable SSL administrator logging.
disable: Disable SSL administrator logging.
option -
sslvpn-log-session Enable/disable SSL session logging.
enable: Enable SSL session logging.
disable: Disable SSL session logging.
option -
vip-ssl Enable/disable VIP SSL logging.
enable: Enable VIP SSL logging.
disable: Disable VIP SSL logging.
option -
ldb-monitor Enable/disable VIP real server health monitoring logging.
enable: Enable VIP real server health monitoring logging.
disable: Disable VIP real server health monitoring logging.
option -
wan-opt Enable/disable WAN optimization event logging.
enable: Enable WAN optimization event logging.
disable: Disable WAN optimization event logging.
option -
wireless-activity Enable/disable wireless activity event logging.
enable: Enable wireless activity event logging.
disable: Disable wireless activity event logging.
option -
cpu-memory-usage Enable/disable CPU & memory usage logging every 5 minutes.
enable: Enable CPU & memory usage logging every 5 minutes.
disable: Disable CPU & memory usage logging every 5 minutes.
option -
filter Disk log filter. string Maximum length: 511
filter-type Include/exclude logs that match the filter.
include: Include logs that match the filter.
exclude: Exclude logs that match the filter.
option -

Configure filters for local disk logging. Use these filters to determine the log messages to record according to severity and type.

  config log disk filter
      Description: Configure filters for local disk logging. Use these filters to determine the log messages to record according to severity and type.
      set severity [emergency|alert|...]
      set forward-traffic [enable|disable]
      set local-traffic [enable|disable]
      set multicast-traffic [enable|disable]
      set sniffer-traffic [enable|disable]
      set anomaly [enable|disable]
      set voip [enable|disable]
      set dlp-archive [enable|disable]
      set gtp [enable|disable]
      set event [enable|disable]
      set system [enable|disable]
      set radius [enable|disable]
      set ipsec [enable|disable]
      set dhcp [enable|disable]
      set ppp [enable|disable]
      set admin [enable|disable]
      set ha [enable|disable]
      set auth [enable|disable]
      set pattern [enable|disable]
      set sslvpn-log-auth [enable|disable]
      set sslvpn-log-adm [enable|disable]
      set sslvpn-log-session [enable|disable]
      set vip-ssl [enable|disable]
      set ldb-monitor [enable|disable]
      set wan-opt [enable|disable]
      set wireless-activity [enable|disable]
      set cpu-memory-usage [enable|disable]
      set filter {string}
      set filter-type [include|exclude]
  end

config log disk filter

Parameter Name Description Type Size
severity Log to disk every message above and including this severity level.
emergency: Emergency level.
alert: Alert level.
critical: Critical level.
error: Error level.
warning: Warning level.
notification: Notification level.
information: Information level.
debug: Debug level.
option -
forward-traffic Enable/disable forward traffic logging.
enable: Enable forward traffic logging.
disable: Disable forward traffic logging.
option -
local-traffic Enable/disable local in or out traffic logging.
enable: Enable local in or out traffic logging.
disable: Disable local in or out traffic logging.
option -
multicast-traffic Enable/disable multicast traffic logging.
enable: Enable multicast traffic logging.
disable: Disable multicast traffic logging.
option -
sniffer-traffic Enable/disable sniffer traffic logging.
enable: Enable sniffer traffic logging.
disable: Disable sniffer traffic logging.
option -
anomaly Enable/disable anomaly logging.
enable: Enable anomaly logging.
disable: Disable anomaly logging.
option -
voip Enable/disable VoIP logging.
enable: Enable VoIP logging.
disable: Disable VoIP logging.
option -
dlp-archive Enable/disable DLP archive logging.
enable: Enable DLP archive logging.
disable: Disable DLP archive logging.
option -
gtp Enable/disable GTP messages logging.
enable: Enable GTP messages logging.
disable: Disable GTP messages logging.
option -
event Enable/disable event logging.
enable: Enable setting.
disable: Disable setting.
option -
system Enable/disable system activity logging.
enable: Enable system activity logging.
disable: Disable system activity logging.
option -
radius Enable/disable RADIUS messages logging.
enable: Enable RADIUS messages logging.
disable: Disable RADIUS messages logging.
option -
ipsec Enable/disable IPsec negotiation messages logging.
enable: Enable IPsec negotiation messages logging.
disable: Disable IPsec negotiation messages logging.
option -
dhcp Enable/disable DHCP service messages logging.
enable: Enable DHCP service messages logging.
disable: Disable DHCP service messages logging.
option -
ppp Enable/disable L2TP/PPTP/PPPoE logging.
enable: Enable L2TP/PPTP/PPPoE logging.
disable: Disable L2TP/PPTP/PPPoE logging.
option -
admin Enable/disable admin login/logout logging.
enable: Enable admin login/logout logging.
disable: Disable admin login/logout logging.
option -
ha Enable/disable HA logging.
enable: Enable HA logging.
disable: Disable HA logging.
option -
auth Enable/disable firewall authentication logging.
enable: Enable firewall authentication logging.
disable: Disable firewall authentication logging.
option -
pattern Enable/disable pattern update logging.
enable: Enable pattern update logging.
disable: Disable pattern update logging.
option -
sslvpn-log-auth Enable/disable SSL user authentication logging.
enable: Enable SSL user authentication logging.
disable: Disable SSL user authentication logging.
option -
sslvpn-log-adm Enable/disable SSL administrator login logging.
enable: Enable SSL administrator logging.
disable: Disable SSL administrator logging.
option -
sslvpn-log-session Enable/disable SSL session logging.
enable: Enable SSL session logging.
disable: Disable SSL session logging.
option -
vip-ssl Enable/disable VIP SSL logging.
enable: Enable VIP SSL logging.
disable: Disable VIP SSL logging.
option -
ldb-monitor Enable/disable VIP real server health monitoring logging.
enable: Enable VIP real server health monitoring logging.
disable: Disable VIP real server health monitoring logging.
option -
wan-opt Enable/disable WAN optimization event logging.
enable: Enable WAN optimization event logging.
disable: Disable WAN optimization event logging.
option -
wireless-activity Enable/disable wireless activity event logging.
enable: Enable wireless activity event logging.
disable: Disable wireless activity event logging.
option -
cpu-memory-usage Enable/disable CPU & memory usage logging every 5 minutes.
enable: Enable CPU & memory usage logging every 5 minutes.
disable: Disable CPU & memory usage logging every 5 minutes.
option -
filter Disk log filter. string Maximum length: 511
filter-type Include/exclude logs that match the filter.
include: Include logs that match the filter.
exclude: Exclude logs that match the filter.
option -