Skip to main content
Visitor II
June 14, 2026
Question

IPsec tunnels Logs Not Consistently Forwarded to FortiSIEM

  • June 14, 2026
  • 1 reply
  • 35 views

 

Hi,
I want to create a correlation rule in FORTISIEM that detects when a VPN tunnel goes down and is not followed by a corresponding tunnel-up event within a defined time window.
 

I have a FortiGate acting as a dial-up IPsec VPN hub for remote devices with forticlient(with auto reconnect) to be always connected 24/7.

some peers generate tunnel-up events that successfully reach FortiSIEM, while other peers generate tunnel-up events locally on the FortiGate but those events never appear in FortiSIEM even though the tunnel is successfully re-established.

Tunnel-down events are received consistently.

Logging level is configured to "All" and I can see tunnel-up/tunnel-down events locally on the FortiGate.
 

Has anyone experienced forwarding of IPsec tunnel-up events or know of any FortiGate logging behavior that could explain this?

Thanks.

1 reply

AEK
SuperUser
SuperUser
June 15, 2026

Hi Saif

  • Which FortiOS version?
  • Do you see the related tunnel-up messages locally on FG logs?
  • In case you are using UDP syslog, try using TCP syslog and see if it helps
AEK