Logs Library

Learn to read, locate, and investigate Firewall, VPN, Windows Event, and Syslog data

Record all inbound and outbound traffic decisions made by network firewalls. Critical for detecting port scans, blocked attacks, and policy violations.

How to Access These Logs

FortiGate / FortiOS

  1. 1Log in to FortiGate GUI → Log & Report → Forward Traffic
  2. 2Or via CLI: execute log filter category 0 then execute log display
  3. 3SIEM ingestion: syslog to port 514 UDP from FortiGate to your SIEM collector
  4. 4Log file location (local): /var/log/traffic.log

Windows Defender Firewall

  1. 1Run: wf.msc → Monitoring → Firewall → Properties
  2. 2Enable logging under each profile (Domain/Private/Public)
  3. 3Log path: %SystemRoot%\System32\logfiles\firewall\pfirewall.log
  4. 4Or query via PowerShell: Get-NetFirewallProfile | Select Name,LogFileName

Palo Alto

  1. 1Device → Log Forwarding Profiles
  2. 2Monitor → Traffic Logs in GUI
  3. 3Export via API: /api/?type=log&log-type=traffic

Sample Log Entries

2026-05-05 08:12:34 FW-EDGE-01 FORWARD src=203.0.113.44 dst=10.0.0.10 sport=49221 dport=443 proto=TCP action=ALLOW rule=WEB-ALLOW bytes=1240

Normal HTTPS traffic allowed to DMZ web server

2026-05-05 08:12:50 FW-EDGE-01 FORWARD src=185.220.101.5 dst=10.0.0.1 sport=54321 dport=22 proto=TCP action=DENY rule=SSH-RESTRICT

SSH blocked, external IP not in allow list

2026-05-05 08:13:01 FW-EDGE-01 FORWARD src=185.220.101.5 dst=10.0.0.1 sport=54322 dport=22 proto=TCP action=DENY rule=SSH-RESTRICT

Repeated SSH block from same IP, possible brute force scan

2026-05-05 08:15:00 FW-EDGE-01 FORWARD src=10.0.2.55 dst=8.8.8.8 sport=53221 dport=53 proto=UDP action=ALLOW rule=DNS-OUT bytes=512

Outbound DNS query — monitor for tunneling

2026-05-05 08:22:14 FW-EDGE-01 DENY src=192.168.3.101 dst=203.0.113.99 sport=44120 dport=4444 proto=TCP action=DENY rule=OUTBOUND-DEFAULT

Blocked outbound connection to uncommon port 4444, possible C2 callback

Common Fields

timestampdevicedirectionsrc_ipdst_ipsrc_portdst_portprotocolactionrulebytes

SOC Investigation Tips

  • Look for the same source IP hitting DENY rules repeatedly — could be a port scan

  • Outbound connections to port 4444, 1337, or high random ports may indicate C2 (Command & Control)

  • ALLOW rules on unexpected ports (e.g., 23/Telnet) should be flagged for review

  • DNS traffic from unexpected hosts or unusually large DNS payloads can indicate DNS tunneling