Configuring syslog settings
A remote syslog server is a system provisioned specifically to collect logs for long term storage and analysis with preferred analytic tools.
Before you begin:
- You must have Read-Write permission for Log & Report settings.
To configure syslog settings:
- Go to Log & Report > Log Setting.
- Click the Syslog Server tab.
- Click Create New to display the configuration editor.
- Complete the configuration as described in Syslog configuration.
- Save the configuration.
Settings | Guidelines |
---|---|
Status | Select to enable the configuration. |
Address | IP address of the syslog server. |
Port | Listening port number of the syslog server. Usually this is UDP port 514. |
Log Level | Select the lowest severity to log from the following choices:
For example, if you select Error, the system sends the syslog server logs with level Error, Critical, Alert, and Emergency. If you select Alert, the system collects logs with level Alert and Emergency. |
CSV | Send logs in CSV format. Do not use with FortiAnalyzer. |
Facility | Identifier that is not used by any other device on your network when sending logs to FortiAnalyzer/syslog. |
Event | Select to enable logging for events. |
Event Category | Select the types of events to send to the syslog server:
|
Traffic | Select to enable logging for traffic processed by the load balancing modules. |
Traffic Category |
|
Security | Select to enable logging for traffic processed by the security modules. |
Security Category |
|
Script | Select to enable scripting. |
Script Category | SLB is elected by default. |