Skip to main content
ispcolohost
New Member
October 11, 2016
Question

Any way to get RFC-compliant syslog messages?

  • October 11, 2016
  • 10 replies
  • 18042 views

Does anyone know if there's a way to get the FortiOS to output syslog messages per RFC 5424 / 3164?  The default format seems to be something proprietary, and doesn't even include the timezone.  What's worse, is there doesn't seem to be consistency between FortiOS and ForitWeb; they spit out events with different field names for the same data, or have different fields the other doesn't, etc.

    10 replies

    emnoc
    New Member
    October 11, 2016

    Yes it "proprietary"  and no i don't think  they will ever  meet rfc compliance. You have raw text or csv for output selections.

     

    Most modern syslog collectors can support one or the other,  but not rfc5242 from the FGT . So your   out of luck and you could ask for a feature request but I highly doubt FTNT will make the logging output  compatible to RFC5424

     

    ispcolohost
    New Member
    October 11, 2016

    We're ingesting syslog data into Graylog, which someone has written a FortiNet-specific module for, but other log analysis tools are of course useless with it being proprietary.  Unfortunately the FortiWeb output is completely useless since it doesn't even match normal FortiOS format, so I guess we'll have to go the custom route for that.

    emnoc
    New Member
    October 11, 2016

    I thought  fortiweb had a  option for rfc enabled output? Have you double check  with support?

     

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!