FortiGate logging to FortiCloud doesn't show policy hits or bytes
I'm remotely managing a diskless FortiGate through FortiCloud, using its Remote Access to do direct management. Logging is supposed to be realtime to FortiCloud.
The FortiGate's security policies only show bytes and hits for a brief time, then they show 0. Maybe they're pulling the data from memory instead of FortiCloud? Any ideas on how or if I can get this data to be correct? Checking the logs I can find these policies getting hit -- they just don't show that they are.
Related to this, selecting a policy and right-clicking to "Show Matching Logs" gets me a set of the most recent, unfiltered, forwarded logs. This used to work correctly.
Maybe an issue with how the FortiGate is pulling logs from FortiCloud?
Thoughts appreciated.
