Forum
31

FortiGate logid 0000000013 is 90% of my log volume. Can I drop it?

asked by shadepl 21 days ago

session close records, hundreds of thousands a day, eating the whole ingest budget. any reason to keep the individual lines

3 answers

Sign in to answer.
dcid (Daniel) 28 points 21 days ago

Drop them, but count them first.

That logid with type="traffic" subtype="forward" action="close" is a session ending normally. Nobody has ever investigated an incident by reading one. The value is entirely in aggregate: which networks your users reach, how much moved, when that changed.

So do not store the lines, do keep counters for destination country, service, bytes.

One thing worth checking while you are in there. Are you logging denies at all? A lot of FortiGates are set up to log accepts and not blocks, which is exactly backwards. Blocked traffic is the interesting half and a fraction of the volume.

shadepl 14 points 21 days ago

...we were not logging denies. thanks, that is embarrassing but useful

mbxsec 7 points 20 days ago

Same thing bit us last year. Default policy had logging set to all sessions on the allow rule and nothing on the implicit deny.

Guidelines Newest Search Back to Trunc