get_logs
Read FortiGate logs newest first to inspect traffic, app control, system events, IPS, and web filtering; filter by IP, policy, or hostname and page results.
Instructions
Read FortiGate logs, newest first. Useful types: traffic/forward (sessions through policies, with app identification), app-ctrl (per-connection application and, with certificate inspection, the HTTPS hostname), event/system (admin and config events), ips, webfilter. FortiGate-VMs without a log disk only keep logs in memory, which is lost on reboot.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| rows | No | Rows to return (default 50, max 1000) | |
| vdom | No | VDOM (default: FORTIGATE_VDOM, usually root) | |
| start | No | Offset for paging (default 0) | |
| fields | No | Only return these fields per row, e.g. [date, time, srcip, dstip, hostname, app, action] | |
| filter | No | FortiOS log filter, e.g. srcip==192.168.150.10 or policyid==1 or hostname=@github | |
| source | No | memory (default), disk, fortianalyzer or forticloud | |
| log_type | Yes | One of: traffic/forward, traffic/local, traffic/multicast, traffic/sniffer, event/system, event/user, event/router, event/vpn, event/wad, event/endpoint, event/ha, event/security-rating, event/fortiextender, event/connector, app-ctrl, ips, virus, webfilter, dns, ssl, ssh, file-filter, anomaly, waf, emailfilter, dlp, voip, gtp, icap, virtual-patch | |
| resolve_vms | No | Label IPs/MACs with the Proxmox VM that owns them (needs PROXMOX_*) |