Fortinet white logo
Fortinet white logo
7.2.1

Log Forwarding

Log Forwarding

FortiAIOps supports direct FortiGate log forwarding and FortiAnalyzer log forwarding.

  • Direct FortiGate log forwarding - Navigate to Log Settings in the FortiGate GUI and specify the FortiManager IP address.

  • FortiAnalyzer log forwarding - Navigate to Log Settings in the FortiGate GUI and enable FortiAnalyzer log forwarding.

    Navigate to Log Forwarding in the FortiAnalyzer GUI, specify the FortiManager Server Address and select the FortiGate controller in Device Filters.

Note: The syslog port is the default UDP port 514.

FortiManager Syslog Configurations

You are required to add a Syslog server in FortiManager, navigate to System Settings > Advanced > Syslog Server. Enter the name, IP address or FQDN of the syslog server (localhost), and the port.

Additionally, configure the following Syslog settings via the CLI mode.

config system locallog syslogd3 setting

set severity information

set status enable

set syslog-name "FortiAIOps"

end

For more information on configuration described in this section, see the FortiManager Administration Guide and Log Message Reference.

Log Forwarding

Log Forwarding

FortiAIOps supports direct FortiGate log forwarding and FortiAnalyzer log forwarding.

  • Direct FortiGate log forwarding - Navigate to Log Settings in the FortiGate GUI and specify the FortiManager IP address.

  • FortiAnalyzer log forwarding - Navigate to Log Settings in the FortiGate GUI and enable FortiAnalyzer log forwarding.

    Navigate to Log Forwarding in the FortiAnalyzer GUI, specify the FortiManager Server Address and select the FortiGate controller in Device Filters.

Note: The syslog port is the default UDP port 514.

FortiManager Syslog Configurations

You are required to add a Syslog server in FortiManager, navigate to System Settings > Advanced > Syslog Server. Enter the name, IP address or FQDN of the syslog server (localhost), and the port.

Additionally, configure the following Syslog settings via the CLI mode.

config system locallog syslogd3 setting

set severity information

set status enable

set syslog-name "FortiAIOps"

end

For more information on configuration described in this section, see the FortiManager Administration Guide and Log Message Reference.