Fortinet white logo
Fortinet white logo

Log Reference

Type

Type

Every FortiMail log message has a type field. When you download a log file from FortiMail, the type is also indicated by the file name.

Field Value

Downloaded File Name

Description

encrypt

nlog.log

FortiMail IBE or S/MIME daemon startup, email signing, encryption, and decryption.

event

elog.log

Mail events such as SMTP daemon startup, undeliverable mail, establishing encrypted transit with STARTTLS, POP3/IMAP/webmail user logins, and FortiMail sending quarantine reports.

kevent

klog.log

System events and management activities, including reboots, software updates, FortiMail configuration changes, and when administrators log in or log out.

virus

vlog.log

Virus detections, FortiGuard Antivirus outbreak protection, and FortiSandbox URL scan results.

statistics

alog.log

History of email received and delivered by that FortiMail system, including the SMTP session ID (session_id) and action (disposition).

Note

The session_id field can be used to correlate an SMTP session across multiple types of log messages (event, encrypt, virus, and spam) to get details about why an email delivery temporarily failed or was rejected. Timestamps may not be as useful as searching by session ID because delivery could be delayed or retried later.

spam

slog.log

Spam detections and quarantine access, including which method was used to determine whether the email was legitimate or spam, and whether there were any processing errors.

Type

Type

Every FortiMail log message has a type field. When you download a log file from FortiMail, the type is also indicated by the file name.

Field Value

Downloaded File Name

Description

encrypt

nlog.log

FortiMail IBE or S/MIME daemon startup, email signing, encryption, and decryption.

event

elog.log

Mail events such as SMTP daemon startup, undeliverable mail, establishing encrypted transit with STARTTLS, POP3/IMAP/webmail user logins, and FortiMail sending quarantine reports.

kevent

klog.log

System events and management activities, including reboots, software updates, FortiMail configuration changes, and when administrators log in or log out.

virus

vlog.log

Virus detections, FortiGuard Antivirus outbreak protection, and FortiSandbox URL scan results.

statistics

alog.log

History of email received and delivered by that FortiMail system, including the SMTP session ID (session_id) and action (disposition).

Note

The session_id field can be used to correlate an SMTP session across multiple types of log messages (event, encrypt, virus, and spam) to get details about why an email delivery temporarily failed or was rejected. Timestamps may not be as useful as searching by session ID because delivery could be delayed or retried later.

spam

slog.log

Spam detections and quarantine access, including which method was used to determine whether the email was legitimate or spam, and whether there were any processing errors.