Fortinet black logo

CLI Reference

log setting cloud

log setting cloud

Use this command to configure storing log messages to the FortiAnalyzer Cloud.

Syntax

config log setting cloud

set status {enable | disable}

set loglevel {alert | critical | debug | emergency | error | information | notification | warning}

set event-log-category {imap | pop3 | smtp | webmail}]

set event-log-status {enable | disable}

set syseventlog-category {admin | configuration | dns | ha | system | update}]

set system-event-log-status {enable | disable}

set antivirus-log-status {enable | disable}

set antispam-log-status {enable | disable}

set history-log-status {enable | disable}

set encryption-log-status {enable | disable}

end

Variable

Description

Default

status {enable | disable}

Enable to send log types which are enabled to FortiAnalyzer Cloud.

enable

loglevel {alert | critical | debug | emergency | error | information | notification | warning}

Enter one or more of the following severity levels:

  • emergency
  • alert
  • critical
  • error
  • warning
  • notification
  • information
  • debug

This log destination will receive log messages greater than or equal to this severity level. For details, see the FortiMail Administration Guide.

information

event-log-category {imap | pop3 | smtp | webmail}]

Enter all of the mail log types and subtypes that you want to record to this storage location. Separate each type with a space.

  • imap: Log all IMAP events.
  • pop3: Log all POP3 events.
  • smtp: Log all SMTP relay or proxy events.
  • webmail: Log all FortiMail webmail events.

webmail stmp

event-log-status {enable | disable}

Enable or disable event logging to FortiAnalyzer Cloud.

webmail smtp

syseventlog-category {admin | configuration | dns | ha | system | update}]

Enter all of the system event log types and subtypes that you want to record to this storage location. Separate each type with a space.

  • admin: Administrative events such as logins, viewing log messages, and resetting the configuration.
  • configuration: Configuration changes by an administrator, such as policies, profiles, and domains.
  • dns: DNS queries.
  • ha: High availability (HA) activity.
  • system: System events, such as rebooting the FortiMail unit or IP address configuration via DHCP. Note: This category does not include events from mail daemons, which are configured in event-log-category [{imap pop3 smtp webmail}].
  • update: Both successful and unsuccessful attempts to download firmware and FortiGuard updates.

admin configuration dns ha system update

system-event-log-status {enable | disable}

Enable to log system events.

enable

antivirus-log-status {enable | disable}

Enable to log all antivirus events.

enable

antispam-log-status {enable | disable}

Enable to log all antispam events.

enable

history-log-status {enable | disable}

Enable to log both successful and unsuccessful attempts by the built-in MTA or proxies to deliver email.

enable

encryption-log-status {enable | disable}

Enable to log all IBE events.

enable

log setting cloud

Use this command to configure storing log messages to the FortiAnalyzer Cloud.

Syntax

config log setting cloud

set status {enable | disable}

set loglevel {alert | critical | debug | emergency | error | information | notification | warning}

set event-log-category {imap | pop3 | smtp | webmail}]

set event-log-status {enable | disable}

set syseventlog-category {admin | configuration | dns | ha | system | update}]

set system-event-log-status {enable | disable}

set antivirus-log-status {enable | disable}

set antispam-log-status {enable | disable}

set history-log-status {enable | disable}

set encryption-log-status {enable | disable}

end

Variable

Description

Default

status {enable | disable}

Enable to send log types which are enabled to FortiAnalyzer Cloud.

enable

loglevel {alert | critical | debug | emergency | error | information | notification | warning}

Enter one or more of the following severity levels:

  • emergency
  • alert
  • critical
  • error
  • warning
  • notification
  • information
  • debug

This log destination will receive log messages greater than or equal to this severity level. For details, see the FortiMail Administration Guide.

information

event-log-category {imap | pop3 | smtp | webmail}]

Enter all of the mail log types and subtypes that you want to record to this storage location. Separate each type with a space.

  • imap: Log all IMAP events.
  • pop3: Log all POP3 events.
  • smtp: Log all SMTP relay or proxy events.
  • webmail: Log all FortiMail webmail events.

webmail stmp

event-log-status {enable | disable}

Enable or disable event logging to FortiAnalyzer Cloud.

webmail smtp

syseventlog-category {admin | configuration | dns | ha | system | update}]

Enter all of the system event log types and subtypes that you want to record to this storage location. Separate each type with a space.

  • admin: Administrative events such as logins, viewing log messages, and resetting the configuration.
  • configuration: Configuration changes by an administrator, such as policies, profiles, and domains.
  • dns: DNS queries.
  • ha: High availability (HA) activity.
  • system: System events, such as rebooting the FortiMail unit or IP address configuration via DHCP. Note: This category does not include events from mail daemons, which are configured in event-log-category [{imap pop3 smtp webmail}].
  • update: Both successful and unsuccessful attempts to download firmware and FortiGuard updates.

admin configuration dns ha system update

system-event-log-status {enable | disable}

Enable to log system events.

enable

antivirus-log-status {enable | disable}

Enable to log all antivirus events.

enable

antispam-log-status {enable | disable}

Enable to log all antispam events.

enable

history-log-status {enable | disable}

Enable to log both successful and unsuccessful attempts by the built-in MTA or proxies to deliver email.

enable

encryption-log-status {enable | disable}

Enable to log all IBE events.

enable