Created on
05-10-2019
05:49 AM
Edited on
05-28-2025
09:32 PM
By
Anthony_E
Description
This article describes how to integrate FortiClient EMS and FortiClient in the FortiAnalyzer so that it can centralize logging.
Scope
FortiAnalyzer.
Solution
Verify the compatibility of the FortiClient EMS server and FortiClient with the FortiAnalyzer. This can be found on the FortiClient release note, on the FortiClient EMS release note (https://docs.fortinet.com/document/forticlient/7.4.0/ems-compatibility-chart), and on the FortiAnalyzer release note (https://docs.fortinet.com/document/fortianalyzer/7.6.3/release-notes/581145/forticlient) .
Note:
The new Fabric ADOM can also be used since FortiAnalyzer 6.2 to receive logs from the FortiClient stations.
Configure the https-logging from FortiAnalyzer via CLI:
port1)# show
config system interface
edit "port1"
set ip 10.47.3.65 255.255.240.0
set allowaccess ping ssh https https-logging
next
end
Connect the FortiClient to the FortiClient EMS server as follows:
Check that the FortiClient EMS detects the client.
Enable Antivirus detection or Web Filter to generate logs from the FortiClient as follows:
Wait for the Configuration update from the Telemetry
Go to the FortiClient and generate logs using a web browser or EICAR virus detection. Navigate here from the FortiClient station to download the EICAR virus detection.
If logs are not turning green, it is possible to check the raw log: logview, logbrowse, and filter by the FortiClient EMS serial to see the FortiClient traffic and event log. Check if any of those logs appear.
Note:
If this is not the case, navigate again from the FortiClient and deregister and register the client once again to generate logs.
If using FortiAnalyzer Cloud, 2 factors can be checked:
FC1-10-AZCLD-463-01-DD
FC2-10-AZCLD-463-01-DD
FC3-10-AZCLD-463-01-DD
Related document:
The
<log_upload_server>12345.ca-west-1.fortianalyzer.forticloud.com</log_upload_server>
<log_uploadserver_sni>12345.support.fortinet.com</log_uploadserver_sni>
Related document:
Related documents:
Technical Tip: Control logging from FortiClient EMS to FortiAnalyzer
DOCS: Configuring log storage policy
Technical Tip: How to make multitenancy visible from FortiAnalyzer
Technical Tip: How to run a FortiClient Endpoint Antivirus scanning using FortiSoC Playbook
Technical Tip: How to determine the failed status from FortiSoC Playbook monitor
Technical Tip: How to send FortiClient logs to FortiAnalyzer
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.