Logs Library
Learn to read, locate, and investigate Firewall, VPN, Windows Event, and Syslog data
Record all inbound and outbound traffic decisions made by network firewalls. Critical for detecting port scans, blocked attacks, and policy violations.
How to Access These Logs
FortiGate / FortiOS
- 1
Log in to FortiGate GUI → Log & Report → Forward Traffic - 2
Or via CLI: execute log filter category 0 then execute log display - 3
SIEM ingestion: syslog to port 514 UDP from FortiGate to your SIEM collector - 4
Log file location (local): /var/log/traffic.log
Windows Defender Firewall
- 1
Run: wf.msc → Monitoring → Firewall → Properties - 2
Enable logging under each profile (Domain/Private/Public) - 3
Log path: %SystemRoot%\System32\logfiles\firewall\pfirewall.log - 4
Or query via PowerShell: Get-NetFirewallProfile | Select Name,LogFileName
Palo Alto
- 1
Device → Log Forwarding Profiles - 2
Monitor → Traffic Logs in GUI - 3
Export via API: /api/?type=log&log-type=traffic
Sample Log Entries
2026-05-05 08:12:34 FW-EDGE-01 FORWARD src=203.0.113.44 dst=10.0.0.10 sport=49221 dport=443 proto=TCP action=ALLOW rule=WEB-ALLOW bytes=1240
Normal HTTPS traffic allowed to DMZ web server
2026-05-05 08:12:50 FW-EDGE-01 FORWARD src=185.220.101.5 dst=10.0.0.1 sport=54321 dport=22 proto=TCP action=DENY rule=SSH-RESTRICT
SSH blocked, external IP not in allow list
2026-05-05 08:13:01 FW-EDGE-01 FORWARD src=185.220.101.5 dst=10.0.0.1 sport=54322 dport=22 proto=TCP action=DENY rule=SSH-RESTRICT
Repeated SSH block from same IP, possible brute force scan
2026-05-05 08:15:00 FW-EDGE-01 FORWARD src=10.0.2.55 dst=8.8.8.8 sport=53221 dport=53 proto=UDP action=ALLOW rule=DNS-OUT bytes=512
Outbound DNS query — monitor for tunneling
2026-05-05 08:22:14 FW-EDGE-01 DENY src=192.168.3.101 dst=203.0.113.99 sport=44120 dport=4444 proto=TCP action=DENY rule=OUTBOUND-DEFAULT
Blocked outbound connection to uncommon port 4444, possible C2 callback
Common Fields
SOC Investigation Tips
Look for the same source IP hitting DENY rules repeatedly — could be a port scan
Outbound connections to port 4444, 1337, or high random ports may indicate C2 (Command & Control)
ALLOW rules on unexpected ports (e.g., 23/Telnet) should be flagged for review
DNS traffic from unexpected hosts or unusually large DNS payloads can indicate DNS tunneling