Created on
11-27-2022
10:24 PM
Edited on
01-06-2025
11:04 PM
By
Jean-Philippe_P
Description | This article describes how to configure secure log-forwarding to a syslog server using an SSL certificate and its common problems. |
Scope | Secure log forwarding. |
Solution |
Configuration Details.
Create a Log Forwarding server under System Settings -> Log Forwarding with the following options enabled:
set fwd-reliable <----- This can be enabled in GUI or CLI. set fwd-secure <----- This can only be enabled in CLI.
By default, it uses Fortinet’s self-signed certificate.
Common Problems:
FortiAnalyzer follows RFC 5424 protocol. But, the syslog server may show errors like 'Invalid frame header; header=''. This usually means the Syslog server does not support the format in which FortiAnalyzer is forwarding logs.
Related articles: Technical Tip: Integrate FortiAnalyzer and FortiSIEM Technical Tip: Forwarding Logs from FortiAnalyzer to Syslog server |