Fortinet black logo

CLI Reference

config log threat-weight

config log threat-weight

Configure threat weight settings.

config log threat-weight
    Description: Configure threat weight settings.
    set status [enable|disable]
    config level
        Description: Score mapping for threat weight levels.
        set low {integer}
        set medium {integer}
        set high {integer}
        set critical {integer}
    end
    set blocked-connection [disable|low|...]
    set failed-connection [disable|low|...]
    set malware-detected [disable|low|...]
    set url-block-detected [disable|low|...]
    set botnet-connection-detected [disable|low|...]
    config ips
        Description: IPS threat weight settings.
        set info-severity [disable|low|...]
        set low-severity [disable|low|...]
        set medium-severity [disable|low|...]
        set high-severity [disable|low|...]
        set critical-severity [disable|low|...]
    end
    config web
        Description: Web filtering threat weight settings.
        edit <id>
            set category {integer}
            set level [disable|low|...]
        next
    end
    config geolocation
        Description: Geolocation-based threat weight settings.
        edit <id>
            set country {string}
            set level [disable|low|...]
        next
    end
    config application
        Description: Application-control threat weight settings.
        edit <id>
            set category {integer}
            set level [disable|low|...]
        next
    end
end

config log threat-weight

Parameter

Description

Type

Size

status

Enable/disable the threat weight feature.

option

-

Option

Description

enable

Enable the threat weight feature.

disable

Disable the threat weight feature.

blocked-connection

Threat weight score for blocked connections.

option

-

Option

Description

disable

Disable threat weight scoring for blocked connections.

low

Use the low level score for blocked connections.

medium

Use the medium level score for blocked connections.

high

Use the high level score for blocked connections.

critical

Use the critical level score for blocked connections.

failed-connection

Threat weight score for failed connections.

option

-

Option

Description

disable

Disable threat weight scoring for failed connections.

low

Use the low level score for failed connections.

medium

Use the medium level score for failed connections.

high

Use the high level score for failed connections.

critical

Use the critical level score for failed connections.

malware-detected

Threat weight score for detected malware.

option

-

Option

Description

disable

Disable threat weight scoring for detected malware.

low

Use the low level score for detected malware.

medium

Use the medium level score for detected malware.

high

Use the high level score for detected malware.

critical

Use the critical level score for detected malware.

url-block-detected

Threat weight score for URL blocking.

option

-

Option

Description

disable

Disable threat weight scoring for URL blocking.

low

Use the low level score for URL blocking.

medium

Use the medium level score for URL blocking.

high

Use the high level score for URL blocking.

critical

Use the critical level score for URL blocking.

botnet-connection-detected

Threat weight score for detected botnet connections.

option

-

Option

Description

disable

Disable threat weight scoring for detected botnet connections.

low

Use the low level score for detected botnet connections.

medium

Use the medium level score for detected botnet connections.

high

Use the high level score for detected botnet connections.

critical

Use the critical level score for detected botnet connections.

config level

Parameter

Description

Type

Size

low

Low level score value .

integer

Minimum value: 1 Maximum value: 100

medium

Medium level score value .

integer

Minimum value: 1 Maximum value: 100

high

High level score value .

integer

Minimum value: 1 Maximum value: 100

critical

Critical level score value .

integer

Minimum value: 1 Maximum value: 100

config ips

Parameter

Description

Type

Size

info-severity

Threat weight score for IPS info severity events.

option

-

Option

Description

disable

Disable threat weight scoring for IPS info severity events.

low

Use the low level score for IPS info severity events.

medium

Use the medium level score for IPS info severity events.

high

Use the high level score for IPS info severity events.

critical

Use the critical level score for IPS info severity events.

low-severity

Threat weight score for IPS low severity events.

option

-

Option

Description

disable

Disable threat weight scoring for IPS low severity events.

low

Use the low level score for IPS low severity events.

medium

Use the medium level score for IPS low severity events.

high

Use the high level score for IPS low severity events.

critical

Use the critical level score for IPS low severity events.

medium-severity

Threat weight score for IPS medium severity events.

option

-

Option

Description

disable

Disable threat weight scoring for IPS medium severity events.

low

Use the low level score for IPS medium severity events.

medium

Use the medium level score for IPS medium severity events.

high

Use the high level score for IPS medium severity events.

critical

Use the critical level score for IPS medium severity events.

high-severity

Threat weight score for IPS high severity events.

option

-

Option

Description

disable

Disable threat weight scoring for IPS high severity events.

low

Use the low level score for IPS high severity events.

medium

Use the medium level score for IPS high severity events.

high

Use the high level score for IPS high severity events.

critical

Use the critical level score for IPS high severity events.

critical-severity

Threat weight score for IPS critical severity events.

option

-

Option

Description

disable

Disable threat weight scoring for IPS critical severity events.

low

Use the low level score for IPS critical severity events.

medium

Use the medium level score for IPS critical severity events.

high

Use the high level score for IPS critical severity events.

critical

Use the critical level score for IPS critical severity events.

config web

Parameter

Description

Type

Size

category

Threat weight score for web category filtering matches.

integer

Minimum value: 0 Maximum value: 255

level

Threat weight score for web category filtering matches.

option

-

Option

Description

disable

Disable threat weight scoring for web category filtering matches.

low

Use the low level score for web category filtering matches.

medium

Use the medium level score for web category filtering matches.

high

Use the high level score for web category filtering matches.

critical

Use the critical level score for web category filtering matches.

config geolocation

Parameter

Description

Type

Size

country

Country code.

string

Maximum length: 2

level

Threat weight score for Geolocation-based events.

option

-

Option

Description

disable

Disable threat weight scoring for Geolocation-based events.

low

Use the low level score for Geolocation-based events.

medium

Use the medium level score for Geolocation-based events.

high

Use the high level score for Geolocation-based events.

critical

Use the critical level score for Geolocation-based events.

config application

Parameter

Description

Type

Size

category

Application category.

integer

Minimum value: 0 Maximum value: 65535

level

Threat weight score for Application events.

option

-

Option

Description

disable

Disable threat weight scoring for Application events.

low

Use the low level score for Application events.

medium

Use the medium level score for Application events.

high

Use the high level score for Application events.

critical

Use the critical level score for Application events.

config log threat-weight

config log threat-weight

Configure threat weight settings.

config log threat-weight
    Description: Configure threat weight settings.
    set status [enable|disable]
    config level
        Description: Score mapping for threat weight levels.
        set low {integer}
        set medium {integer}
        set high {integer}
        set critical {integer}
    end
    set blocked-connection [disable|low|...]
    set failed-connection [disable|low|...]
    set malware-detected [disable|low|...]
    set url-block-detected [disable|low|...]
    set botnet-connection-detected [disable|low|...]
    config ips
        Description: IPS threat weight settings.
        set info-severity [disable|low|...]
        set low-severity [disable|low|...]
        set medium-severity [disable|low|...]
        set high-severity [disable|low|...]
        set critical-severity [disable|low|...]
    end
    config web
        Description: Web filtering threat weight settings.
        edit <id>
            set category {integer}
            set level [disable|low|...]
        next
    end
    config geolocation
        Description: Geolocation-based threat weight settings.
        edit <id>
            set country {string}
            set level [disable|low|...]
        next
    end
    config application
        Description: Application-control threat weight settings.
        edit <id>
            set category {integer}
            set level [disable|low|...]
        next
    end
end

config log threat-weight

Parameter

Description

Type

Size

status

Enable/disable the threat weight feature.

option

-

Option

Description

enable

Enable the threat weight feature.

disable

Disable the threat weight feature.

blocked-connection

Threat weight score for blocked connections.

option

-

Option

Description

disable

Disable threat weight scoring for blocked connections.

low

Use the low level score for blocked connections.

medium

Use the medium level score for blocked connections.

high

Use the high level score for blocked connections.

critical

Use the critical level score for blocked connections.

failed-connection

Threat weight score for failed connections.

option

-

Option

Description

disable

Disable threat weight scoring for failed connections.

low

Use the low level score for failed connections.

medium

Use the medium level score for failed connections.

high

Use the high level score for failed connections.

critical

Use the critical level score for failed connections.

malware-detected

Threat weight score for detected malware.

option

-

Option

Description

disable

Disable threat weight scoring for detected malware.

low

Use the low level score for detected malware.

medium

Use the medium level score for detected malware.

high

Use the high level score for detected malware.

critical

Use the critical level score for detected malware.

url-block-detected

Threat weight score for URL blocking.

option

-

Option

Description

disable

Disable threat weight scoring for URL blocking.

low

Use the low level score for URL blocking.

medium

Use the medium level score for URL blocking.

high

Use the high level score for URL blocking.

critical

Use the critical level score for URL blocking.

botnet-connection-detected

Threat weight score for detected botnet connections.

option

-

Option

Description

disable

Disable threat weight scoring for detected botnet connections.

low

Use the low level score for detected botnet connections.

medium

Use the medium level score for detected botnet connections.

high

Use the high level score for detected botnet connections.

critical

Use the critical level score for detected botnet connections.

config level

Parameter

Description

Type

Size

low

Low level score value .

integer

Minimum value: 1 Maximum value: 100

medium

Medium level score value .

integer

Minimum value: 1 Maximum value: 100

high

High level score value .

integer

Minimum value: 1 Maximum value: 100

critical

Critical level score value .

integer

Minimum value: 1 Maximum value: 100

config ips

Parameter

Description

Type

Size

info-severity

Threat weight score for IPS info severity events.

option

-

Option

Description

disable

Disable threat weight scoring for IPS info severity events.

low

Use the low level score for IPS info severity events.

medium

Use the medium level score for IPS info severity events.

high

Use the high level score for IPS info severity events.

critical

Use the critical level score for IPS info severity events.

low-severity

Threat weight score for IPS low severity events.

option

-

Option

Description

disable

Disable threat weight scoring for IPS low severity events.

low

Use the low level score for IPS low severity events.

medium

Use the medium level score for IPS low severity events.

high

Use the high level score for IPS low severity events.

critical

Use the critical level score for IPS low severity events.

medium-severity

Threat weight score for IPS medium severity events.

option

-

Option

Description

disable

Disable threat weight scoring for IPS medium severity events.

low

Use the low level score for IPS medium severity events.

medium

Use the medium level score for IPS medium severity events.

high

Use the high level score for IPS medium severity events.

critical

Use the critical level score for IPS medium severity events.

high-severity

Threat weight score for IPS high severity events.

option

-

Option

Description

disable

Disable threat weight scoring for IPS high severity events.

low

Use the low level score for IPS high severity events.

medium

Use the medium level score for IPS high severity events.

high

Use the high level score for IPS high severity events.

critical

Use the critical level score for IPS high severity events.

critical-severity

Threat weight score for IPS critical severity events.

option

-

Option

Description

disable

Disable threat weight scoring for IPS critical severity events.

low

Use the low level score for IPS critical severity events.

medium

Use the medium level score for IPS critical severity events.

high

Use the high level score for IPS critical severity events.

critical

Use the critical level score for IPS critical severity events.

config web

Parameter

Description

Type

Size

category

Threat weight score for web category filtering matches.

integer

Minimum value: 0 Maximum value: 255

level

Threat weight score for web category filtering matches.

option

-

Option

Description

disable

Disable threat weight scoring for web category filtering matches.

low

Use the low level score for web category filtering matches.

medium

Use the medium level score for web category filtering matches.

high

Use the high level score for web category filtering matches.

critical

Use the critical level score for web category filtering matches.

config geolocation

Parameter

Description

Type

Size

country

Country code.

string

Maximum length: 2

level

Threat weight score for Geolocation-based events.

option

-

Option

Description

disable

Disable threat weight scoring for Geolocation-based events.

low

Use the low level score for Geolocation-based events.

medium

Use the medium level score for Geolocation-based events.

high

Use the high level score for Geolocation-based events.

critical

Use the critical level score for Geolocation-based events.

config application

Parameter

Description

Type

Size

category

Application category.

integer

Minimum value: 0 Maximum value: 65535

level

Threat weight score for Application events.

option

-

Option

Description

disable

Disable threat weight scoring for Application events.

low

Use the low level score for Application events.

medium

Use the medium level score for Application events.

high

Use the high level score for Application events.

critical

Use the critical level score for Application events.