Chapter 3 Authentication for FortiOS 5.0 : SSO using RADIUS accounting records : Creating the FortiGate RADIUS SSO agent : Configuring logging for RSSO
  
Configuring logging for RSSO
In the config user radius CLI command, you can set the following flags in the rsso-log-flags field to determine which types of RSSO-related events are logged:
accounting-event — FortiOS did not find the expected information in a RADIUS record.
accounting-stop-missed — a user context entry expired without FortiOS receiving a RADIUS Stop message.
context-missing — FortiOS was not able to match a communication session with a user.
endpoint-block — FortiOS blocked a user because the RADIUS record’s endpoint block attribute had the value “Block”.
profile-missing — FortiOS cannot find a user group name in a RADIUS start message that matches the name of an RSSO user group in FortiOS.
protocol-error — A RADIUS protocol error occurred.
radiusd-other — Other events, described in the log message.