Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
sarathharidas99
New Contributor

Logging Fortinet firewall configuration changes to ArcSight

Hi,

 

 I need help with the list of Fortigate system event ID’s for configuration changes. The event IDs should include all tasks as mentioned below:-

 

  • All actions taken by any individual with root or administrative privileges – includes updates and other system changes (not just rules)
  • Access to all audit trails
  • Invalid logical access attempts
  • Use of and changes to identification and authentication mechanisms—including but not limited to creation of new accounts and elevation of privileges—and all changes, additions, or deletions to accounts with root or administrative privileges
  • Initialization, stopping, or pausing of the audit logs
  • Creation and deletion of system-level objects[/ul]

    Please help with the same.

  • 0 REPLIES 0
    Labels
    Top Kudoed Authors