Chapter 13 Logging and Reporting : Logging and reporting overview : FortiOS features available for logging : Traffic
  
Traffic
Traffic logs record the traffic that is flowing through your FortiGate unit. Since traffic needs firewall policies to properly flow through the unit, this type of logging is also referred to as firewall policy logging. Firewall policies control all traffic that attempts to pass through the FortiGate unit, between FortiGate interfaces, zones and VLAN sub-interfaces.
Logging traffic works in the following way:
firewall policy has logging enabled on it (Log Allowed Traffic or Log Violation Traffic)
packet comes into an inbound interface
a possible log packet is sent regarding a match in the firewall policy, such as URL filter
traffic log packet is sent, per firewall policy
packet passes and is sent out an interface
Traffic log messages are stored in the traffic log file. Traffic logs can be stored any log device, even system memory.
All Security Feature-related logs are now tracked within the Traffic logs, as of FortiOS 5.0, so all forward traffic an be searched in one place, such as if you are looking to see all activity from a particular address, security feature or traffic.
The Security Feature Log section has been removed from the default interface, but if your device is registered with FortiCloud, Security Log may still appear in the web interface, and will list the security feature traffic separately, as FortiCloud tracks it separately from traffic. If you would like to be able to view the security feature logs both within and isolated from the Traffic logs, registering with FortiCloud is necessary.
If you have enabled and configured WAN Optimization, you can enable logging of this activity in the CLI using the config wanopt setting command. These logs contain information about WAN Optimization activity and are found in the traffic log file. When configuring logging of this activity, you must also enable logging within the security policy itself, so that the activity is properly recorded.