Skip to main content
Mahlako
New Member
January 22, 2021
Question

Adding second SYSLOG Server

  • January 22, 2021
  • 2 replies
  • 15130 views

we configure fortigate device to send logs to FortiAnalyzer via syslog they are 6.0. we have SYSLOG server configured on the client's VDOM.

Now I need to add another SYSLOG server on all VDOMs on the firewall.

 

How do I add the other syslog server on the vdoms without replacing the current ones? 

 

    2 replies

    Yurisk
    SuperUser
    SuperUser
    January 22, 2021

    Fortigate can send logs to max 4 Syslog servers, so you configure the second server using the same commands but syslogd2 on CLI. 

    More info here https://kb.fortinet.com/kb/documentLink.do?externalID=FD44614 

    https://docs.fortinet.com/document/fortigate/6.2.1/cli-reference/356620/log-syslogd2-setting 

     

    yurisk.info - all things Fortinet blog, no ads
    ede_pfau
    SuperUser
    SuperUser
    January 22, 2021

    just curious: why would you send logs to a FAZ via syslog? FAZ uses it's own protocol for this, adding the benefit of obtaining log data that can be searched, cumulated and charted - all of which cannot be done with 'plain' syslog data.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!