Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Baptiste
Contributor II

Message alert since FAZ 6.0.0

Hi all,

On my FGT, I activate message alert when admin login/logout.

Since I update FAZ to 6.0.0, I receive several time a day theses messages for each firewall.

Do you have same behaviour ?

 

Message meets Alert condition date=2018-05-02 time=02:45:54 devname=FGT60E-XXXXX devid=FGT60EXXXXXXX logid="0100032001" type="event" subtype="system" level="information" vd="root" eventtime=1525221954 logdesc="Admin login successful" sn="XXXXXXX" user="admin" ui="http(127.0.0.1)" method="http" srcip=127.0.0.1 dstip=127.0.0.1 action="login" status="success" reason="none" profile="super_admin" msg="Administrator admin logged in successfully from http(127.0.0.1)"

 

2 FGT 100D  + FTK200

3 FGT 60E  FAZ VM  some FAP 210B/221C/223C/321C/421E

2 FGT 100D + FTK200 3 FGT 60E FAZ VM some FAP 210B/221C/223C/321C/421E
3 REPLIES 3
MarisDr
New Contributor

I do have exactly the same behaviour.

Any explanations?

chall_FTNT

If you have security fabric enabled on the FortiGate, then FortiAnalyzer will try to login to the FortiGate to gather security fabric statistics & topology information.

 

For this to work properly you must setup a security fabric group in FortiAnalyzer which includes proper admin credentials in order for FortiAnalyzer to log into the FortiGate.

Chris Hall
Fortinet Technical Support
Baptiste

thanks for this explanation.

I follow this guide and it's working fine with only read access on system config.

But I still have a lot false positive : if I set Upload option to "reatime" :

 

Message meets Alert condition date=2018-06-07 time=15:27:00 devname=FGT60E-Xxx devid=FGT60E logid="0100032001" type="event" subtype="system" level="information" vd="root" eventtime=1528378020 logdesc="Admin login successful" sn=" xxx " user="faz-user" ui="http(127.0.0.1)" method="http" srcip=127.0.0.1 dstip=127.0.0.1 action="login" status="success" reason="none" profile="faz-user-group" msg="Administrator faz-user logged in successfully from http(127.0.0.1)" Message meets Alert condition date=2018-06-07 time=15:26:00 devname=FGT60E-Xxx devid=FGT60E logid="0100032001" type="event" subtype="system" level="information" vd="root" eventtime=1528377959 logdesc="Admin login successful" sn=" xxx " user="faz-user" ui="http(127.0.0.1)" method="http" srcip=127.0.0.1 dstip=127.0.0.1 action="login" status="success" reason="none" profile="faz-user-group" msg="Administrator faz-user logged in successfully from http(127.0.0.1)" Message meets Alert condition date=2018-06-07 time=15:25:00 devname=FGT60E-Xxx devid=FGT60E logid="0100032001" type="event" subtype="system" level="information" vd="root" eventtime=1528377899 logdesc="Admin login successful" sn=" xxx " user="faz-user" ui="http(127.0.0.1)" method="http" srcip=127.0.0.1 dstip=127.0.0.1 action="login" status="success" reason="none" profile="faz-user-group" msg="Administrator faz-user logged in successfully from http(127.0.0.1)" Message meets Alert condition date=2018-06-07 time=15:23:59 devname=FGT60E-Xxx devid=FGT60E logid="0100032001" type="event" subtype="system" level="information" vd="root" eventtime=1528377839 logdesc="Admin login successful" sn=" xxx " user="faz-user" ui="http(127.0.0.1)" method="http" srcip=127.0.0.1 dstip=127.0.0.1 action="login" status="success" reason="none" profile="faz-user-group" msg="Administrator faz-user logged in successfully from http(127.0.0.1)" Message meets Alert condition date=2018-06-07 time=15:22:59 devname=FGT60E-Xxx devid=FGT60E logid="0100032001" type="event" subtype="system" level="information" vd="root" eventtime=1528377779 logdesc="Admin login successful" sn=" xxx " user="faz-user" ui="http(127.0.0.1)" method="http" srcip=127.0.0.1 dstip=127.0.0.1 action="login" status="success" reason="none" profile="faz-user-group" msg="Administrator faz-user logged in successfully from http(127.0.0.1)" Message meets Alert condition date=2018-06-07 time=15:21:59 devname=FGT60E-Xxx devid=FGT60E logid="0100032001" type="event" subtype="system" level="information" vd="root" eventtime=1528377719 logdesc="Admin login successful" sn=" xxx " user="faz-user" ui="http(127.0.0.1)" method="http" srcip=127.0.0.1 dstip=127.0.0.1 action="login" status="success" reason="none" profile="faz-user-group" msg="Administrator faz-user logged in successfully from http(127.0.0.1)" Message meets Alert condition date=2018-06-07 time=15:21:29 devname=FGT60E-Xxx devid=FGT60E logid="0100032001" type="event" subtype="system" level="information" vd="root" eventtime=1528377689 logdesc="Admin login successful" sn=" xxx " user="faz-user" ui="http(127.0.0.1)" method="http" srcip=127.0.0.1 dstip=127.0.0.1 action="login" status="success" reason="none" profile="faz-user-group" msg="Administrator faz-user logged in successfully from http(127.0.0.1)" Message meets Alert condition date=2018-06-07 time=15:20:59 devname=FGT60E-Xxx devid=FGT60E logid="0100032001" type="event" subtype="system" level="information" vd="root" eventtime=xxx logdesc="Admin login successful" sn="xxx" user="faz-user" ui="http(127.0.0.1)" method="http" srcip=127.0.0.1 dstip=127.0.0.1 action="login" status="success" reason="none" profile="faz-user-group" msg="Administrator faz-user logged in successfully from http(127.0.0.1)" Message meets Alert condition date=2018-06-07 time=15:20:02 devname=FGT60E-Xxx devid=FGT60E logid="0100032001" type="event" subtype="system" level="information" vd="root" eventtime=xxx logdesc="Admin login successful" sn="xxx" user="faz-user" ui="http(127.0.0.1)" method="http" srcip=127.0.0.1 dstip=127.0.0.1 action="login" status="success" reason="none" profile="faz-user-group" msg="Administrator faz-user logged in successfully from http(127.0.0.1)"

 

I think Fortinet can find another way to get this working without this spam engine

2 FGT 100D  + FTK200

3 FGT 60E  FAZ VM  some FAP 210B/221C/223C/321C/421E

2 FGT 100D + FTK200 3 FGT 60E FAZ VM some FAP 210B/221C/223C/321C/421E
Labels
Top Kudoed Authors