Skip to main content
kwernecke
Staff
Staff
November 24, 2021

Technical Tip: How to Gather FortiEDR Collector Logs Locally

  • November 24, 2021
  • 0 replies
  • 5106 views
Description This article describes how to gather collector logs when it is disconnected or not shown in the console for Windows, OSX, and Linux.
Scope FortiEDR Collector Logging 5.0+
Solution

For Windows:

Open the Command Prompt as Administrator

Run the following command:

 

"C:\Program Files\Fortinet\FortiEDR\FortiEDRCollectorService.exe" --support


Gather the files from the following location:

 

%TEMP%\program_data_archive_support.zip

 

Upload to the case in FortiCare.

 

For macOS:

 

/Applications/FortiEDR.app/FortiEDRCollector --support

 

For v6.0+ execute the command:

 

sudo /Applications/FortiEDR.app/Contents/MacOS/FortiEDRCollector.app/Contents/MacOS/FortiEDRCollector --support

 

For Linux:

 

/opt/FortiEDRCollector/bin/FortiEDRCollector --support

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!