Skip to main content
david_pereira
Staff & Editor
Staff & Editor
July 8, 2026

Technical Tip: Validating FortiClient EMS Integration with FortiAnalyzer

  • July 8, 2026
  • 0 replies
  • 38 views

Description

This article describes procedures for validating the integration between FortiClient EMS and FortiAnalyzer, verifying log forwarding, and confirming that endpoint events are correctly recorded.

Scope

FortiClient, EMS, FortiAnalyzer.

Solution

Logs forwarded from EMS to FortiAnalyzer.
FortiClient EMS can forward several categories of logs to FortiAnalyzer, including:

  • Traffic Logs: Network traffic generated by managed endpoints.

  • Event Logs: Endpoint events, software updates, and FortiClient system events.

  • Security Event Logs: Malware protection, web filtering, vulnerability scan results, and application firewall events.

  • Vulnerability Logs: Events generated by endpoint vulnerability scans.


Verify the log configuration.

Confirm that the required log types are enabled in the FortiClient EMS profile:

  1. Navigate to Endpoint Profiles -> System Settings -> <Profile Name> -> Log.

  2. Enable the required log categories, such as:

  • UTM Logs.

  • System Event Logs.

  • Vulnerability Logs.

  • Event Logs.


Log volume and expected logging behavior.

Log volume.

The volume of forwarded logs depends on the number of managed endpoints and the log categories enabled in FortiClient EMS. FortiAnalyzer does not limit log generation; storage consumption is determined by the configured ADOM storage policy.

Expected behavior.

When the integration is functioning correctly, logs should be forwarded to FortiAnalyzer in near real time. If expected logs are not visible in the graphical interface, verify whether they are present by using logview or logbrowse.



Storage utilization and log retention.


Storage utilization.

Storage usage depends on the amount of collected log data and the configured retention policy. Configure the ADOM storage policy according to operational and compliance requirements.


For additional information, refer to Configuring Log Storage Policy in the FortiAnalyzer Administration Guide.


Log retention.

Confirm that the ADOM storage policy is configured to retain logs for the required retention period.


Event visibility when additional EMS features are enabled.

Enabling additional FortiClient EMS features, such as Advanced Threat Protection or Application Control, may generate additional event logs. These events should become visible in FortiAnalyzer under their corresponding log categories after the features are enabled and events are generated.


Validating the EMS-to-FortiAnalyzer workflow.

Perform the following validation steps:

  1. Verify the integration.
    Confirm that FortiClient EMS is successfully integrated with FortiAnalyzer.

    Verify that both systems report a healthy connection status.

  2. Confirm log reception.

    Open the 'Log View' section in FortiAnalyzer.
    Verify that the expected endpoint log categories are being received.

    If only system events are displayed, confirm that the required log types are enabled in the assigned EMS endpoint profile.

  3. Perform troubleshooting (if necessary).

    Deregister and re-register the FortiClient endpoint to trigger the generation of new events.

    Verify that all required licenses and entitlements are valid.

    When using FortiAnalyzer Cloud, confirm that the required XML feature flags and service configurations are correctly applied.