Description
This article describes how to enable Syslog logging by using protocol: UDP in FortiSOAR to send log to FortiAnalyzer.
Scope
FortiSOAR, FortiAnalyzer
Solution
- Login into FortiSOAR GUI, select the small little Settings icon on the top-right corner.

- Navigate to System -> System Configuration -> Log Forwarding. It is possible to configure all the FortiAnalyzer mandatory configuration data, such as IP address, protocol, port number, and log type to be forwarded (Audit Logs, Application Logs). Audit Logs level can be set to Basic or Detailed, and it is possible to define an Audit Log forwarding rule to match a specific condition -> Save.

- Login into FortiAnalyzer to authorize the FortiSOAR to join the logging request, wait a couple of minutes for the device request to appear in the Device Manager and then authorize it into an ADOM.


- In the FortiAnalyzer again, navigate to Log View -> FortiSOAR, and it will be possible to view the ingested event log from the FortiSOAR.
