Skip to main content
aagrafi
New Member
December 5, 2017
Question

Sending logs from FAD to FAZ

  • December 5, 2017
  • 1 reply
  • 5607 views

Hello,

 

In the training notes of FortiADC, it is stated that FAD logs can be sent to FAZ. However in the FAD there is specific button for registering FAD to FAZ. I'm assuming that FAD can only send logs to FAZ only using syslog, but I'm not sure. Can somebody confirm, or tell me if there is some other way to send logs from FAD to FAZ?

 

Thanks

Andreas

    1 reply

    chall_FTNT
    Staff
    Staff
    December 5, 2017

    FortiADC is not a recognized Fortinet device type by FortiAnalyzer at this time.  But FortiAnalyzer can accept syslog logging from FortiADC.

    aagrafi
    aagrafiAuthor
    New Member
    December 6, 2017

    Thanks for the reply. In that case, what level/quality of analysis/reporting/queries/etc. can we expect from the FAZ regarding those logs, considering that the FAD has sent them as raw log data? Also, do we need to create a separate ADOM to accept these logs?

     

    Andreas

    chall_FTNT
    Staff
    Staff
    December 6, 2017

    As long as you enabled ADOMS, there is a default ADOM for syslog traffic.

     

    In the FortiAnalyzer Release Notes, see Product Integration and Support >> Feature support.  It shows that LogView & Event Management are supported for Syslog.  But not FortiView or Reports.