Technical Tip: FortiAnalyzer secure log forwarding
| Description | This article describes how to configure secure log-forwarding to a syslog server using an SSL certificate and its common problems. |
| Scope | Secure log forwarding. |
| Solution | Configuration Details.
Create a Log Forwarding server under System Settings -> Log Forwarding with the following options enabled:
set fwd-reliable <----- This can be enabled in GUI or CLI. set fwd-secure <----- This can only be enabled in CLI.
By default, it uses Fortinet’s self-signed certificate.
Common Problems:
FortiAnalyzer follows RFC 5424 protocol. But, the syslog server may show errors like 'Invalid frame header; header=''. This usually means the Syslog server does not support the format in which FortiAnalyzer is forwarding logs.
Note: Log forwarding is not supported on FortiManager, including when FortiAnalyzer features are enabled.
Related articles: |

