What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

FortiMail logs can help identify a suspicious email, its handling and scanning results, and administrative activity on the FortiMail appliance. They do not establish that a file was opened on a separate server or that a web shell was requested or run. Use gateway records to identify leads, then verify file and web-shell activity with logs and telemetry from the affected host.

Which FortiMail logs should you review?

Start with history or statistics records to identify the message and the action FortiMail took. Fortinet describes history logs as records of the unit’s action; their fields and labels can vary by release, so consult the log reference for the installed version (FortiMail log types).

Record type What it covers Investigative use
statistics / history (alog) Email traffic through relay or proxy and the action or disposition Locate the message, determine its disposition, and use its session ID to pivot to related records.
event (elog) Mail activity including SMTP, POP3, IMAP, and webmail Reconstruct relevant mail-protocol or webmail activity around the message.
virus (vlog) Virus detections; cited subtypes include infected, malware-outbreak, and file-signature Review attachment detections, signatures, and scan results.
kevent (klog) System management, configuration changes, and administrator or user logins and logouts Check for unexpected administrative activity on the FortiMail appliance.
spam (slog) Spam detection events Add classification context when the same message or session appears.

These type names and fields are not guaranteed to be identical across releases. Fortinet documents the session-ID correlation in its FortiMail 7.6.3 logging guide; subtype details are listed in the FortiMail 8.0.0 subtype reference.

How to correlate the records

Fortinet says email-related logs carry a session ID that corresponds across relevant log types. Use the Session ID link or Cross Search, where available, to gather the history, event, antivirus, and antispam records for the same activity. A session ID helps connect gateway records; it does not prove that a recipient opened an attachment or that a server executed a file.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Fortinet FortiMail FML-200F Network Security/Firewall Applianc - 4 Port - 10/100/1000Base-T Gigabit Ethernet - 4 x RJ-45 - 1U - Rack-mountable
  • FortiMail is a top-rated secure email gateway that stops volume-based and targeted cyber threats to help secure the dynamic enterprise attack surface, prevents the loss of sensitive data and helps
  • High performance physical and virtual appliances deploy on-site or in the public cloud to serve any size organization - from small businesses to carriers, service providers, and large enterprises
  • Threat Prevention Powerful antispam and antimalware, are complemented by advanced techniques like outbreak protection, content disarm and reconstruction, sandbox analysis, impersonation detection
  • Data Protection Robust data loss prevention, identitybased email encryption and archiving help prevent the inadvertent loss of sensitive information and maintain compliance with corporate and
  • Security Fabric Integration Integrations with Fortinet products as well as third-party components help customers adopt a proactive approach to security by sharing IoCs across a seamless Security
  1. Set the incident window. Record the suspected interval in UTC, the FortiMail version and operating mode, relevant protected domains and policies, and which local or remote log stores are available.
  2. Find candidate messages. In Monitor > Log or the remote logging system, inspect history or statistics records for the relevant recipient, sender, or time range. Capture the session ID, time, sender, recipient, disposition, source or client information, and subject or message identifier when present.
  3. Pivot on the session ID. Open Cross Search or follow the session ID to retrieve related event, antivirus, and antispam records. Record which expected record types are absent rather than assuming they were never generated.
  4. Review attachment detections. In antivirus records, note the subtype, attachment name and type if available, detection or signature name, scan outcome, and any FortiSandbox or FortiNDR analysis.
  5. Check appliance administration. Review kevent entries for logins, configuration changes, updates, and other management actions. Compare the account, source or interface, action, status, and timestamp with authorized administrative work.
  6. Verify host activity separately. Pivot to the implicated recipient endpoint or web server and examine its own web, file, process, authentication, and network records to test whether the attachment was opened, written, or executed, or whether a web shell was requested or invoked.
  7. Preserve the evidence. Export original records where possible, note collection times and time zones, and document coverage gaps before drawing conclusions.

What antivirus records can—and cannot—show

FortiMail antivirus logs cover messages classified as virus or suspicious and can identify the detected threat or affected attachment. What the gateway detects depends on the configured antivirus profile. Fortinet documents scanning of headers, bodies, attachments, and compressed attachments, with optional heuristic, file-signature, FortiNDR, and FortiSandbox analysis in its antivirus profile configuration guide.

Capture the available attachment indicators and compare them with known indicators using your approved incident-response process. FortiMail file-signature checks can use configured SHA-1 or SHA-256 values for supported attachment formats. A file that does not match a configured signature is not thereby proven benign; an unmatched result only means that the configured check did not report a match.

Rank #2
Fortinet FortiMail-200F Hardware Plus 1 Year 24x7 FortiCare and FortiGuard Enterprise ATP Bundle FML-200F-BDL-641-12
  • FortiMail is a top-rated secure email gateway that stops volume-based and targeted cyber threats to help secure the dynamic enterprise attack surface, prevents the loss of sensitive data and helps
  • High performance physical and virtual appliances deploy on-site or in the public cloud to serve any size organization - from small businesses to carriers, service providers, and large enterprises
  • Threat Prevention Powerful antispam and antimalware, are complemented by advanced techniques like outbreak protection, content disarm and reconstruction, sandbox analysis, impersonation detection
  • Data Protection Robust data loss prevention, identitybased email encryption and archiving help prevent the inadvertent loss of sensitive information and maintain compliance with corporate and
  • Security Fabric Integration Integrations with Fortinet products as well as third-party components help customers adopt a proactive approach to security by sharing IoCs across a seamless Security

What proves file access or web-shell activity?

FortiMail is an email-security gateway. Its documented logs cover mail handling and protocols, email threat detections, and activity on the appliance. They do not establish server-side file opens, changes to a web directory, or web-shell command execution. Treat a suspicious message or attachment detection as context or a lead—not as proof of behavior on another system.

  • Web-server evidence: Review the affected server’s access and error logs for requests to suspicious paths, unusual methods, parameters, or timing. A request in an access log alone does not establish successful command execution.
  • File evidence: Examine filesystem timestamps and available file-audit records for unexpected creation or modification of web-accessible files. Preserve the original records and account for timestamp and timezone differences.
  • Process and endpoint evidence: Use host or endpoint telemetry to determine whether a suspicious file was written, opened, or executed, and whether the web-server process launched unexpected child processes or commands.
  • Authentication and network evidence: Correlate relevant logins and network records with the web requests and host events to assess who or what initiated the activity and whether related systems were contacted.

The reviewed Fortinet documentation does not prescribe a particular host-forensics workflow. Choose collection and preservation steps appropriate to your incident-response procedures; do not substitute FortiMail logs for evidence generated by the host.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to interpret missing records

An empty search is not enough to rule out activity. FortiMail logging can be configured by severity and sent to local storage or remote destinations such as a Syslog server or FortiAnalyzer. Before treating an absent entry as meaningful, check whether the relevant categories were enabled, the severity threshold included the event, forwarding was configured, the records remain within retention, the clock is aligned, and the searched logs match the installed version. Fortinet describes these logging options in its 7.6.3 logging guide and 8.0.0 logging guide.

Rank #4
FORTINET FortiGate-1801F Network Security Appliance (FG-1801F)
  • FORTINET FortiGate-1801F Network Security Appliance (FG-1801F)
  • The FortiGate 1801F delivers high performance next generation firewall (NGFW) capabilities for large enterprises and service providers. With multiple high-speed interfaces, high-port density and highthroughput, ideal deployments are at the enterprise edge, hybrid and hyperscale data center core and across internal segments. Leverage industry-leading IPS, SSL inspection and advanced threat protection to optimize your network’s performance.
  • Custom SPU processors deliver the power you need to detect malicious content at multi-Gigabit speeds; Other security technologies cannot protect against today’s wide range of content and connection-based threats because they rely on general-purpose CPUs, causing a dangerous performance gap.
  • Hardware: 198 Gbps | IPS: 13 Gbps | NGFW: 11 Gbps | Threat Protection: 9.1 Gbps; Interface: 4 x 40 GE QSFP+ slots, 12 x 25 GE SFP28 /10GE SFP+ slots, 2x10GE SFP+ HA slots, 8 x GE SFP slots, 18 x GE RJ45 ports, SPU NP7 and CP9 hardware accelerated, 2x 1TB on board SSD storage

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.