This forum is for all security enthusiasts to discuss Fortinet's latest & evolving technologies and to connect & network with peers in the cybersecurity hemisphere. Share and learn on a broad range of topics like best practices, use cases, integrations and more. For support specific questions/resources, please visit the Support Forum or the Knowledge Base.
Hey guys,
Is there a way to import logs stored in an external storage, into FAZ without having the Fortigate that generated the logs logging to this FAZ ?
Thanks
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Thanks for the response.
I've tried this on FortiAnalyzer 5.2 and this doesn't work, it's needed that the FortiGate that generated the logs, is actually registered on FAZ.
I'm talking about having a dedicated FAZ to reporting (no a single FGT registered), and eventually pulling random logs from an external storage device.
Could you please attach a small sample log that you were tring to import to the FAZ 5.2?
I was able to import your log file on my FAZ-VM that is running 5.4 interim build - see attached screenshots for details. You need to take the following steps:
I am trying to pull the local disk logs from a 3000D to a FAZ VM, both are 5.4.1 and I am getting an internal error on the import. Is there anyway to do this? I have a PoC where the partner did not install a FAZ and the customer wants some really nice reports. It's only 3 days of data but 300-400 Mbps customer environment so should be decent amount of data.
Hi Jason
I got the same result as you, if I use the following settings for downloading logs:
Log file format = Native
Compress With gzip "check"
As a workaround:
Keep log file format as “Native” and uncheck "Compress With gzip", this worked for me. I'll open a Mantis as it seems there is a problem with “gzip”.
Many thanks, Roland
Hi Roland
It solved my problem...
Thanks for your advice and support :)
Jason
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.