FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
smkml
Staff
Staff
Article Id 244327
Description

This article describes how to control logs sent from FortiClient EMS to FortiAnalyzer.

Scope

FortiClient EMS 7.0, FortiAnalyzer.

Solution

Some users will notice that in related ADOM that have FortiClients, it receives a huge amount of logs. For the FortiClient, there are 3 types of logs that will populate in LogView which are Traffic, Event, and Vulnerability Scan

 

FortiAnalyzer will not be able to control the size of the logs received, as it depends on the ADOM storage. The ADOM then depends on the log storage policy to maintain the logs.

 

Related document:

https://docs.fortinet.com/document/fortianalyzer/7.2.1/administration-guide/743670/configuring-log-s...

 

To control the type of logs sent, it can be done from FortiClient EMS from: 

Endpoint Profiles -> System Settings -> (Profile Name) -> Log.

 

smkml_2-1675110212039.png

 

To categorize the base on FortiAnalyzer LogView go to

 

1) Upload UTM Logs -> Traffic.

2) Upload System Event -> Event (endpoint control, update, and FortiClient events).

3) Upload Security Event -> Event (Malware Protection, Web Filter, Vulnerability Scan, and Application Firewall events).

4) Upload Vulnerability Logs -> Vulnerability Scan

5) Upload Event Logs -> Event.

 

Related articles:

https://community.fortinet.com/t5/FortiAnalyzer/Technical-Tip-How-to-integrate-EMS-in-the-FortiAnaly...

https://community.fortinet.com/t5/FortiAnalyzer/Troubleshooting-Tip-How-to-investigate-log-visibilit... 

Contributors