Event Log
The Event Log pane provides an audit log of actions made by users on FortiManager. It allows you to view log messages that are stored in memory or on the internal hard disk drive. You can use filters to search the messages and download the messages to the management computer.
See the FortiManager Log Message Reference, available from the Fortinet Document Library, for more information about the log messages.
The event log includes logs for modify, request, and response API calls. You can disable or enable JSON API request and response logging in the FortiManager CLI: config system global set jsonapi-log {all | disable | request | response} all - logging for both jsonapi request & response. disable - disable jsonapi logging for both request & response. request - logging for jsonapi request only. response - logging for jsonapi response only. |
Go to System Settings > Event Log to view the local log list.
The following options are available:
Last... |
Select the amount of time to show from the available options, or select a custom time span or any time. |
|
Add Filter |
Filter the event log list based on the log level, user, sub type, or message. See Event log filtering. |
|
Download |
Download the event logs in either CSV or the normal format to the management computer. |
|
Raw Log / Formatted Log |
Click on Raw Log to view the logs in their raw state. Click Formatted Log to view them in the formatted into a table. |
|
Historical Log |
Click to view the historical logs list. |
|
|
Back |
Click the back icon to return to the regular view from the historical view. |
|
View |
View the selected log file. This option is also available from the right-click menu, or by double-clicking on the log file. This option is only available when viewing historical event logs. |
|
Delete |
Delete the selected log file. This option is also available from the right-click menu. This option is only available when viewing historical event logs. |
|
Clear |
Clear the selected file of logs. This option is also available from the right-click menu. This option is only available when viewing historical event logs. |
|
Type |
Select the type from the dropdown list:
This option is only available when viewing historical logs. |
|
Search |
Enter a search term to search the historical logs. This option is only available when viewing historical event logs. |
Pagination |
Browse the pages of logs and adjust the number of logs that are shown per page. |
The following information is shown:
# |
The log number. |
Date/Time |
The date and time that the log file was generated. |
Level |
The severity level of the message. For a description of severity levels, see the Log Message Reference. |
User |
The user that the log message relates to. |
Sub Type |
The event log subtype. For a description of the subtypes for event logs, see the Log Message Reference. |
Description |
A description of the event. |
Operation |
The change or operation that triggered the event. |
Performed On |
Entity affected by the change or operation. For example, when you log out of the FortiManager GUI, the operation is performed on the local FortiManager GUI. |
Changes |
Details of the change. |
Message |
Log message details. A Session ID is added to each log message. The username of the administrator is added to log messages wherever applicable for better traceability. |