Technical Tip: Enabling remote logging to FortiAnalyzer or third-party Syslog server
| Description | This article describes a few features that the licensed-FortiClient allows users to enable, like logging to a Fortinet FortiAnalyzer device or to a third-party Syslog device, and shows how to enable this feature using the EMS-server GUI and XML. |
| Scope | License-FortiClient v7.2.x, 7.4.x. |
| Solution | Licensed-FortiClient user after connecting to telemetry to the EMS-Server can be configured to send logs to either a Fortinet FortiAnalyzer device or a Syslog Server by XML.
For the configuration, follow the steps below:
  The Event Log Settings 'Log Level' will determine the log level used with a Fortinet FortiAnalyzer/Syslog-Server device. In the example below it used all default values on.
Note: Wireshark can be used to collect traffic flow between the source and the logging server for troubleshooting purposes. |





