FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
iyotov
Staff
Staff
Article Id 376418
Description

 

This article explains a common scenario in which FortiAnalyzer Cloud ignores log messages from EMS, FortiClient, and FortiMail, despite these products being listed as 'supported platforms'.

 

Scope

 

FortiAnalyzer Cloud.

 

Solution

 

The base FortiAnalyzer Cloud entitlement supports only FortiGates, with log limits as per this document: Logging support and daily log limits.

At least one additional storage license (i.e. FC1-10-AZCLD-463-01-DD) is required to enable FortiAnalyzer Cloud to receive logs from EMS, FortiClient, and FortiMail.

 

To confirm the correct entitlement, go to Asset Management -> Account Services:

 

2025-02-13 15_53_11-Asset Management — Mozilla Firefox.png