FortiClient
FortiClient proactively defends against advanced attacks. Its tight integration with the Security Fabric enables policy-based automation to contain threats and control outbreaks. FortiClient is compatible with Fabric-Ready partners to further strengthen enterprises’ security posture.
david_pereira
Article Id 257227
Description This article describes how to send logs from managed FortiClient endpoints to FortiAnalyzer.
Scope FortiClient endpoints that are managed by EMS.
Solution

Access the EMS with admin privileges:

 

Img001.jpg

 

Go to Endpoint Profiles -> System Setting:

 

Img002.jpg

 

Select the desired profile and then select 'Edit':

 

Img003.jpg

 

Then scroll down to the Log part and select the option 'Upload Logs to FortiAnalyzer/FortiManager':

 

Img004.jpg

 

Select the desired logs.

It is possible to change the telemetry interval, which means the frequency at which the FortiClient will send the logs to the FortiAnalyzer.

 

Make sure to configure the FortiAnalyzer IP address or FQDN and port more below:

 

Img005.jpg

 

Select 'Save' at the end.

After that, the logs will be sent to the FortiAnalyzer as well. It can show logs related to FortiClient traffic, all events, and also will show vulnerability logs. 

 

EMS 10.png


Related article:

Technical Tip: How to integrate EMS in the FortiAnalyzer