Skip to main content
mmarchetti
New Member
October 10, 2025
Question

Log not shown as expected

  • October 10, 2025
  • 10 replies
  • 1161 views

Hi all,

i've got an infrastructure of cluster fortigate running 7.4.5 managed by fortimanager. One of this cluster is in the headquarter all the others are branch offices. All of the clusters send logs to the fortianalyzer and all the branch offices send also syslog to a syslog collector behind the headquarter cluster.

 

When looking in the fortianalyzer pointing the headquarter cluster i can see all the branch offices send the events via syslog, but if i point the branch offices to see the events exit from the firewall i can see them only from one branch office and all the others are not showed. I'll past the config from the one i can see and from the other that not. To me they seems the same

This is the one not working:

fw-xxxxx-xxxxxxxxxxxx-o~-01 (setting) # get
resolve-ip : disable
resolve-port : enable
log-user-in-upper : disable
fwpolicy-implicit-log: enable
fwpolicy6-implicit-log: disable
extended-log : disable
local-in-allow : disable
local-in-deny-unicast: disable
local-in-deny-broadcast: disable
local-out : enable
local-out-ioc-detection: enable
daemon-log : disable
neighbor-event : disable
brief-traffic-format: disable
user-anonymize : disable
expolicy-implicit-log: disable
log-policy-comment : disable
faz-override : disable
syslog-override : disable
rest-api-set : disable
rest-api-get : disable
long-live-session-stat: enable
custom-log-fields :

 

This is the one that working

fw-xxxxx-xxxxxxxxxx~-01 (setting) # get
resolve-ip : disable
resolve-port : enable
log-user-in-upper : disable
fwpolicy-implicit-log: disable
fwpolicy6-implicit-log: disable
extended-log : disable
local-in-allow : disable
local-in-deny-unicast: disable
local-in-deny-broadcast: disable
local-out : enable
local-out-ioc-detection: enable
daemon-log : disable
neighbor-event : disable
brief-traffic-format: disable
user-anonymize : disable
expolicy-implicit-log: disable
log-policy-comment : disable
faz-override : disable
syslog-override : disable
rest-api-set : disable
rest-api-get : disable
long-live-session-stat: enable
custom-log-fields :

 

Please help

 

Thanks in advance

10 replies

funkylicious
SuperUser
SuperUser
October 10, 2025

hi,

so if i understand correctly, you have multiple firewalls/clusters in hq and remote locations and all send logs to fortianalyzer and the remote ones send also to a syslog ?

one fortigate/cluster is sending logs to the syslog but the others dont ?

can you do a , show full log syslogd setting on the one that works and one that doesnt ?

"jack of all trades, master of none"
mmarchetti
New Member
October 13, 2025

Hi, i'm sorry. The problem it's seem like all of the branch office execpt one don't log the syslog traffic that originated from the gateway itself, but all the logging are working fine

rosatechnocrat
Explorer III
October 12, 2025

can you simplify the query or problem. 

Is the remote branches not sending logs to Fortianalyzer and sending to syslog server ? 

Subscribe "ROSA Technocrat" on Youtube for Fortinet Videos and Troubleshooting https://www.youtube.com/@rosatechnocrat
mmarchetti
New Member
October 13, 2025

All of them sending log correctly as i can see from fortianalyzer selecting the head quarter. If on fortianalyzer i select the branch office to see the log i can see only from one branch office not for the others. I hope it's more clear now

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!