FortiAnalyzer Connector
When you create a connector for FortiAnalyzer, you are specifying how FortiADC can communicate with FortiAnalyzer for pushing logs to FortiAnalyzer.
FortiADC will connect to FortiAnalyzer by UDP, TCP or TCP SSL depending on the FortiAnalyzer connector setting.
Requirements:
- The FortiAnalyzer service is required to be exposed on External IP.
To create a FortiAnalyzer Connector:
- Go to Security Fabric > Fabric Connectors.
- Click Create New.
- Under Other Fortinet Products, select FortiAnalyzer.
- Configure the following Syslog Server options, and then click Save.
Status Toggle on/off to enable/disable the Fabric Connector object.
Address Type the IP address of the FortiAnalyzer Log server. Port Specify the port that FortiADC uses to communicate with the log server.
Proto
Select the protocol used for log transfer from the following:
UDP
TCP
TCP SSL
TCP Framing
Select one of the following options:
Traditional
Octet Counted
This field appears only if Proto is TCP or TCP SSL.
Log Level
Select the severity level of the logs. All the exported logs will be attached with the selected severity level.
CSV
Enable to export the logs in .csv file.
Facility
Select the source facility of the logs. We only support the local use facilities which are not reserved and are available for general use.
Event
Enable to export Event logs.
Traffic
Enable to export Traffic logs.
Security
Enable to export Security logs.
After the connector is created, FortiADC will push the logs to FortiAnalyzer server. The above configurations are also available in Log&Report > Log Setting > Syslog Server.