Skip to main content
MOHAMMAD_ALAVI
New Member
February 20, 2013
Question

THE LOGS NOT RECEIVED

  • February 20, 2013
  • 8 replies
  • 14192 views
Dear guys, i' ve installed a FAL VM (with trial license) in order to evaluate it . i' ve set my FG to connect to FAL and it' s done successfully. and in FAL devices i can see the FG . but when i try to send the logs to FAL, i encounter with the message THE LOGS NOT RECEIVED . someone help me

    8 replies

    CorneJvV
    New Member
    February 20, 2013
    Are you have any VDOM' s enabled ? If yes, make sure about Static Routes and VDOM Links. I had the same issue a while ago, but I can' t remember how I solved it. It was something basic that I overlooked (all I can remember).
    Dave_Hall
    New Member
    February 20, 2013
    Make sure the fgt device privileges are set correctly in the FA.
    MOHAMMAD_ALAVI
    New Member
    February 20, 2013
    The VDOM feature is disabled in FG ... And about the privileges, all of them has selected ...
    Dave_Hall
    New Member
    February 20, 2013
    Go into the event log (on the fgt) and confirm there are events showing. If not, you may need to reformat the logging device. Next, in the Log&Report->Log Setting->Upload logs remotely->FortiAnalyzer->click the Test Connectivity button -- tell us what the Connection Summary says.
    MOHAMMAD_ALAVI
    New Member
    February 20, 2013
    Dear guys, i' m a FCNSA and FCNSP certified ... so i' ve done every advanced diagnosis you might think of . so just advise me some advanced tshoot ... i know the basic of joining a FortiAnalyzer with a FG
    CorneJvV
    New Member
    February 21, 2013
    I had the same issues about five months ago with a new appliance in our environment. I can' t remember what the solution was, but I do remember looking at it and thinking to myself, what a basic thing that was overlooked.
    MOHAMMAD_ALAVI
    New Member
    February 21, 2013
    Well i' m sure that i' ve done every basic step and also i' ve checked the Test connectivity on the FG and all the fields was ok except the LOGS status which showed " LOGS NOT RECEIVED " . so i thought that maybe something blocking the traffic . as you know the FG and FAL uses Syslog protocol and port 514 in order to sending and receiving logs . i' ve checked the session on FAL and realized that FG has initiated a session to FAL with mentioned port ... even i ' ve captured the traffic on FG and analyzed it with WIRESHARK and it seemed that the FG sending the correct traffic and i' ve found it checking the HEX section of traffic . that is all i' ve done .
    Fullmoon
    New Member
    February 25, 2013
    Do this under fortigate device. FWFXXX# config log fortianalyzer setting FWF6XXX(setting) # set upload-option realtime FWFXXX (setting) # end good luck :)
    emorillo
    New Member
    March 4, 2013
    I had a similar problem with a FA-100C: The FG200B was running 4.0 MR2 Patch 8 The FA100C was running 4.0 MR3 Patch 1 Everything was working fine. I updated FG200B to 5.0 Patch 1 and the FortiAnalyzer stopped receiving logs, it said " LOGS NOT RECEIVED" . I tried many many things but in the end I updated the FortiAnalyzer to 5.0 Patch 1 and it started receiving logs again. Cheers!
    Matthijs
    New Member
    March 5, 2013
    What software versions do you use?
    Ralph1973
    New Member
    March 19, 2013
    Hi, I run into the same issue here. I am preconfiguring a FA400c at home, to be used in our company when I am ready testing etc. I have connected some Fortigates (60c, 60B, 100d) and only the 60B sends its logs to the FA. I took the Fortigate Cookbook and noticed that it says this: Before configuring the FortiGate unit, ensure both the FortiGate unit and the FortiAnalyzer unit have the same firmware version and maintenance release. If both do not have the same firmware version and maintenance release, issues may arise, such as being unable to send logs to the FortiAnalyzer unit. Well, while typing this I see it doesn' t say ' Patch level' , so I can interpret this as it should be okay when the FGT and FA run on 4.0 MR3 with any patchlevel. But I still don' t know why it doesn' t work. Maybe need to configure a FW policy to permit traffic to port 514 or so? Kind regards, Ralph Willemsen Arnhem, Netherlands
    Ralph1973
    New Member
    March 29, 2013
    Well it works now, I figured out, that upgrading to 5.01 did the trick. I am not really happy with that, since I think this version is not free from bugs though.