Skip to main content
olivern4
Explorer III
August 19, 2024
Solved

Fortigate Syslog Timer

  • August 19, 2024
  • 4 replies
  • 1976 views

Hi All,

 

I'm trying to find out how to configure our FG100D (6.2.14-FW-build1364-230411) to send to our Syslog Server (ELK) just every 5 mins. There is no option in the WebUI or even in the CLI to configure this. Is there any way to do this? All I can see is in the FortiAnalyzer option.

 

Thank you.

 

Oliver

Best answer by ozkanaltas

Hello @olivern4 ,

 

Syslog is an instant protocol, so unlike FortiAnalyzer, there is no store-and-forward option on the FortiGate.

4 replies

ozkanaltas
Valued Contributor III
August 19, 2024

Hello @olivern4 ,

 

Syslog is an instant protocol, so unlike FortiAnalyzer, there is no store-and-forward option on the FortiGate.

olivern4
olivern4Author
Explorer III
August 19, 2024

Hi @ozkanaltas 

 


Thank you for the response.

Meaning there is no way to do this? Okay. Can I just use the FortiAnalyzer option instead as the Syslog? I will just add the IP address of the ELK server right?

Thank you.

Oliver

SonaMuvv
Staff
Staff
August 19, 2024

Hello Oliver,

You can get Fortianalyzer/Fortianalyzer cloud license and then configure that on the Fortigate to send logs to Fortianalyzer every 5 minutes.

https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/712303/configuring-fortianalyzer

But you cannot use ELK server ip to configure Fortianalyzer, because when you configure Fortianalyzer it will be configured in the security fabric, which uses separate daemon/ports to forward logs to FortiAnalyzer.

 

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!