Skip to main content
LTC_FAZ
New Member
March 8, 2016
Question

Log aggregation from FAZ client to server fails

  • March 8, 2016
  • 2 replies
  • 7074 views

Hi,

 

1. Using log aggregation authorization fails. On the manual page 171 (http://docs.fortinet.com/...inistration-Guide.pdf) . I can seet that manual says that we must configure password under FAZ server "config system aggregation-service" which is the same as on FAZ client. But there are no such commands available in the CLI. In the dashboard alert messages I can see alerts that log aggregation failed because of bad "auth method". How to enable password command? 2. I tried also with other option which is more granular - Fetcher management (page 173.). I have configured both sides with identical passwords and users, but when I press fetch now, other side does not receive request (also auth failed), and it can not be approved manually. I suppose that request could not be successful because log aggregation is not configured first of all.

 

Maybe some suggestions about the problem?

 

Regards,

2 replies

scao_FTNT
Staff
Staff
March 8, 2016

5.2 or 5.4 FAZ? 5.4 FAZ changed design and will use system settings admin user for client to authenticate (so no need to config password on server side but client side need to configure with correct server side admin user/pass)

 

Thanks

 

Simon

Mikael_A
New Member
March 15, 2016

Got the same issue. Interested if there is a solution.

scao_FTNT
Staff
Staff
March 21, 2016

Hi, Mikael, is your issue also for 5.4 FAZ aggregate mode? is both client and server running on 5.4 and re-configured admin user/password on client?

 

Thanks

 

Simon

Mikael_A
New Member
March 22, 2016

Hi Simon! Yeah, it is.

 

Running 2 VM:s that are using 5.4 software. One in Collector Mode and one is in Analyze mode.

I tried following a guide to the best of my abilities. But it was for 5.2 so some things have changed.

However, let me see if I can give you as much information as possible.

 

The FG that is acting as the device is only added in the Collector FAZ.

On the Collector I´ve setup a connection to the Analyzer under the Log Forwarding option under settings.

Using "Enable Log Aggregation" and a User and password is set.

 

Obviously I need to configure that on the Analyzer as well but the CLI command that did it for 5.2 doesn´t seem to be present in 5.4 How do I configure the Analyzer with the username and password?