To filter what type of logs are sent to disk, use the "log disk filter". This filter does not explicitly mention event logs. Instead the same level of event logging is sent to all log destinations.
So the key is to enable disk logging BUT disable all
configurable options in the "log disk filter". You can use
the template below. Use the "get" command to check whether
your firmware release has any other log sub-types which must be
disabled in addition to the ones included in the template.
End Result: You are left with only event logging sent to disk.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.