Technical Tip: Validating FortiClient EMS Integration with FortiAnalyzer
Description | This article describes procedures for validating the integration between FortiClient EMS and FortiAnalyzer, verifying log forwarding, and confirming that endpoint events are correctly recorded. |
Scope | FortiClient, EMS, FortiAnalyzer. |
Solution | Logs forwarded from EMS to FortiAnalyzer.
Verify the log configuration. Confirm that the required log types are enabled in the FortiClient EMS profile:
Log volume and expected logging behavior. The volume of forwarded logs depends on the number of managed endpoints and the log categories enabled in FortiClient EMS. FortiAnalyzer does not limit log generation; storage consumption is determined by the configured ADOM storage policy. When the integration is functioning correctly, logs should be forwarded to FortiAnalyzer in near real time. If expected logs are not visible in the graphical interface, verify whether they are present by using logview or logbrowse.
Storage usage depends on the amount of collected log data and the configured retention policy. Configure the ADOM storage policy according to operational and compliance requirements.
Confirm that the ADOM storage policy is configured to retain logs for the required retention period.
Enabling additional FortiClient EMS features, such as Advanced Threat Protection or Application Control, may generate additional event logs. These events should become visible in FortiAnalyzer under their corresponding log categories after the features are enabled and events are generated.
Perform the following validation steps:
|
