Skip to main content
shawnwaldman
New Member
February 27, 2018
Solved

FortiAnalyzer Logging Stops

  • February 27, 2018
  • 1 reply
  • 11683 views

I have a FortiGate 200E that is setup to log to the FortiAnalyzer. From time to time, I'll log in to the Analyzer and notice that logging has stopped. Does anyone know how to setup an alert that will notify us that logging has stopped on the FortAnalyzer? I can fix it by logging in to the FortiGate and toggling the logging from real-time to every minute, that seems to get it going again. 

 

Shawn

    Best answer by adawson_van_FTNT

    Please be advised that in FortiAnalyzer firmware version 6.0, the default configuration has changed to 1440 minutes 

     

    FAZ-VM64-Bridged # get system locallog setting log-interval-dev-no-logging: 1440

     

    Therefore, the FortiAnalyzer will wait 24 hours to perform the log check and therefore generate a System Event Log if no logs have been received by the device.

     

    However, it is important to consider that lowering this value and therefore increasing the frequency may hinder device performance.

    1 reply

    hzhao_FTNT
    Staff
    Staff
    February 28, 2018

    Hi Shawn,

     

    By default, there will be some system event logs about "Device offline" as below:

     

    2018-02-27 11:30:15 log_id=0029038009 type=event subtype=logdev pri=warning desc="Device offline" user="system" userfrom="system" msg="Device[xxxxxxxxxxxxxx] did not receive any log in last xx minutes."

     

    In root ADOM, you can create an event handler based on this log and enable "Send Alert Email" on it.

     

    Regards,

    hz

    emnoc
    New Member
    February 28, 2018

    Agreed and that's what we do. Generate a alert trigger for the device and devid and fire it off.

     

    Ken

    adawson_van_FTNT
    Staff
    Staff
    January 18, 2019

    Please be advised that in FortiAnalyzer firmware version 6.0, the default configuration has changed to 1440 minutes 

     

    FAZ-VM64-Bridged # get system locallog setting log-interval-dev-no-logging: 1440

     

    Therefore, the FortiAnalyzer will wait 24 hours to perform the log check and therefore generate a System Event Log if no logs have been received by the device.

     

    However, it is important to consider that lowering this value and therefore increasing the frequency may hinder device performance.