Skip to main content
Contributor III
May 28, 2010
Question

Unable to LOG anything to a syslog server

  • May 28, 2010
  • 17 replies
  • 17788 views
Hello, I' m getting mad. I' m unable to send any log messages to a syslog server installed in a PC. The syslog server works, but the Fortigate doesn' t send anything to it. It' s a Fortigate 200B, firm 4.0 build 0178 (MR1). I think everything is configured as it should, interfaces are set log enable, and policy rules I would like to log are log allowed. But it doesn' t work. I' m getting mad. Do I need to reset the firewall after configure logging ? Can I restart log service only ? Firmware bug ? Thanks

    17 replies

    hidayet
    New Member
    May 28, 2010
    Hi Silvio, Check the link below; http://docs.forticare.com/fgt/techdocs/fortigate-logging_reporting.pdf
    Contributor III
    May 28, 2010
    Hi hidayet, I followed that guide some days ago to configure logging, but my problems remain. There must be something I missed, but I can´t find what. The syslog server has the same IP C class, and there isn' t any firewall betweeen both. I can´t understand why I don' t receive logs. I think I need some help. Thanks
    hidayet
    New Member
    May 28, 2010
    If documentation is done by setting up and running
    rwpatterson
    New Member
    May 28, 2010
    What firmware is on the FAZ?
    Contributor III
    May 28, 2010
    I am trying to send log messages to a syslog server installed on a PC. It' s working properly , but no messages from the FGT
    jmac
    New Member
    May 29, 2010
    Use the FortiGate packet sniffer to verify syslog output: diag sniff packet any " udp and port 514" Verify the source address (FortiGate interface IP) and destination IP. If no packets, possibly a FortiGate issue or configuration (verify default syslog port in FortiGate). If packets, then a syslog receiver issue (verify client IP/port/firewall/etc).
    Contributor III
    June 1, 2010
    Hi again, I tried diag sniff packet any " udp and port 514" and no packets appear, so no traffic comes out ot any interface in that port. get log syslogd setting confirms port 514. I don' t know what to do. Thanks
    red_adair
    New Member
    June 1, 2010
    running sniffer and do a # diagnose log test Any output ? Did you enable " Event Logs" and Login/Logout ? This is the most trivial case to generate a Logentry. I assume you have Syslog-Server IP entered correctly ? in GUI or via # config log syslogd setting -R.
    Contributor III
    June 1, 2010
    I ran that diagnose log test in a ssh window while running diag sniff packet any " udp and port 514" in other ssh window, and no packets appeared in this window after the first command executing, so I think something happens with my Fortigate. Event logs are all enabled, and the IP is correctly configured. But I can see no packets come out of any interface, even with diagnose log test. Thanks
    SECCON1MC
    New Member
    June 1, 2010
    I have seen in the past where a reboot is needed to get logs rolling through syslog or FAZ after adjustments have been made. Try killing the logging process via the CLI or just reboot the box.
    Contributor III
    June 1, 2010
    That' s a good idea, but could you tell me how to kill the log service and restart it from the CLI ? I have no idea how to do it
    SECCON1MC
    New Member
    June 1, 2010
    from the CLI -
    diag sys top
    output looks something like this -
    Run Time: 1 days, 5 hours and 28 minutes 0U, 0S, 99I; 249T, 107F, 75KF newcli 18431 R 0.1 5.0 sshd 18414 S 0.1 4.0 httpsd 59 S 0.0 6.9 httpsd 16043 S 0.0 6.9 cmdbsvr 17 S 0.0 6.1 httpsd 29 S 0.0 5.7 newcli 18426 S 0.0 5.0 ipsengine 49 S < 0.0 4.7 miglogd 27 S 0.0 4.6 scanunitd 28236 S < 0.0 4.4 merged_daemons 43 S 0.0 4.3 fdsmgmtd 58 S 0.0 4.2 iked 56 S 0.0 4.1 thttp 47 S 0.0 4.1 scanunitd 28231 S < 0.0 4.1 updated 57 S 0.0 4.1 authd 51 S 0.0 4.0 snmpd 60 S 0.0 4.0 dhcpd 61 S 0.0 4.0
    identify the process ID for the logging subsystem (miglogd), in this case 27 Kill the process
    diag sys kill 9 <process id>
    The watchdog daemon will restart the process. Check to make sure logs are flowing via some packet sniffing
    diag sniffer packet any ' port 514'  4  
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!