Fortinet black logo

Administration Guide

Admin auditing

Copy Link
Copy Doc ID 868f1267-7299-11e9-81a4-00505692583a:159530
Download PDF

Admin auditing

The Admin auditing log tracks all changes made to an item in the system. Users with admin auditing permissions will see a change in the admin auditing log whenever data is added, modified, or deleted. Users can see what was changed, when the change was made, and who made the change.

Note

Changes made through the CLI are tracked in the admin auditing log; however, the user ID for the user who made the change will appear as "CLI Tool".

Changes can be filtered by the name of the item that was changed, the action taken, the date when the change occurred, the user ID for the user who made the change, and the type of item that was changed.

Note

Changes made to the following items are not currently audited:

  • Trap MIB Files
  • NTP and Time Zone settings
  • Adapters
  • RADIUS Domain Mappings
  • RADIUS Server Defaults (Primary RADIUS Server Default, Secondary RADIUS Server Default)
  • Security Applications
  • Alarms
  • Certificates
  • Portal SSL Settings
  • Portal Configuration Styles
  • Mobile Providers
  • Database Backup settings (excluding the Backup Timeout)
  • Changes to the License Key
Note

Changing the name of a device or moving a device to a new container will result in a separate audit entry for each port on the device.

Note

Similar to Events and Alarms, Admin Auditing archives and purges audits made to Hosts, Users, or Elements.

Admin auditing

The Admin auditing log tracks all changes made to an item in the system. Users with admin auditing permissions will see a change in the admin auditing log whenever data is added, modified, or deleted. Users can see what was changed, when the change was made, and who made the change.

Note

Changes made through the CLI are tracked in the admin auditing log; however, the user ID for the user who made the change will appear as "CLI Tool".

Changes can be filtered by the name of the item that was changed, the action taken, the date when the change occurred, the user ID for the user who made the change, and the type of item that was changed.

Note

Changes made to the following items are not currently audited:

  • Trap MIB Files
  • NTP and Time Zone settings
  • Adapters
  • RADIUS Domain Mappings
  • RADIUS Server Defaults (Primary RADIUS Server Default, Secondary RADIUS Server Default)
  • Security Applications
  • Alarms
  • Certificates
  • Portal SSL Settings
  • Portal Configuration Styles
  • Mobile Providers
  • Database Backup settings (excluding the Backup Timeout)
  • Changes to the License Key
Note

Changing the name of a device or moving a device to a new container will result in a separate audit entry for each port on the device.

Note

Similar to Events and Alarms, Admin Auditing archives and purges audits made to Hosts, Users, or Elements.