Fortinet black logo

Handbook

System Events

6.0.0
Copy Link
Copy Doc ID 4afb0436-a998-11e9-81a4-00505692583a:328798
Download PDF

System Events

The System Events console lists security events detected by FortiOS, providing a name and description for the events, an assessment of the event's severity level (Alert, Critical, Emergency, Error, or Warning), and the number of instances the events were detected.

Two other FortiView pages from 5.4 have been wrapped into the System Events page as of 5.6: Admin Logins, and Failed Authentication.

This console can be filtered by Event Name, Result, and Severity. For more on filters, see Filtering options.

Scenario: Investigate network security events

System Events can be used in conjunction with All Sessions to see what network security events took place, and specifically see what action was taken upon their detection:

  1. Go to FortiView > System Events to see what and how many network events have taken place, as well as how severe they are in terms of the threat they pose to the network.
  2. You see that a particular event has warranted a severe rating, and has allowed traffic to bypass the firewall. Note when the event took place, and go to FortiView > All Sessions, to see more information pertaining to the security event.
  3. From this console, you can determine the system event's source, how much traffic was sent and received, and the security action taken in response to this security event. These actions differ, depending upon the severity of the security event. See the entry for Security Action in Columns displayed.

    note icon

    Only FortiGate models 100D and above support the 24 hour historical data.

System Events

The System Events console lists security events detected by FortiOS, providing a name and description for the events, an assessment of the event's severity level (Alert, Critical, Emergency, Error, or Warning), and the number of instances the events were detected.

Two other FortiView pages from 5.4 have been wrapped into the System Events page as of 5.6: Admin Logins, and Failed Authentication.

This console can be filtered by Event Name, Result, and Severity. For more on filters, see Filtering options.

Scenario: Investigate network security events

System Events can be used in conjunction with All Sessions to see what network security events took place, and specifically see what action was taken upon their detection:

  1. Go to FortiView > System Events to see what and how many network events have taken place, as well as how severe they are in terms of the threat they pose to the network.
  2. You see that a particular event has warranted a severe rating, and has allowed traffic to bypass the firewall. Note when the event took place, and go to FortiView > All Sessions, to see more information pertaining to the security event.
  3. From this console, you can determine the system event's source, how much traffic was sent and received, and the security action taken in response to this security event. These actions differ, depending upon the severity of the security event. See the entry for Security Action in Columns displayed.

    note icon

    Only FortiGate models 100D and above support the 24 hour historical data.