FortiClient
FortiClient proactively defends against advanced attacks. Its tight integration with the Security Fabric enables policy-based automation to contain threats and control outbreaks. FortiClient is compatible with Fabric-Ready partners to further strengthen enterprises’ security posture.
ika
Staff
Staff
Article Id 360967
Description

This article describes how to avoid delay in sending FortiClient logs to FortiAnalyzer.

Scope EMS on-prem and Cloud
Solution

Sometimes FortiAnalyzer will be delayed receiving the FortiClient logs in real-time when all log types (UTM, System Event, Security Event, Software Inventory, OS Events, and etc) were enabled to send.

 

Amend below default setting in EMS can fix the delay issue.

Navigate to EMS GUI -> Endpoint Profiles -> System Settings -> select desired endpoint profiles -> Edit -> Log -> Upload Logs to FortiAnalyzer/FortiManager.

 

Items Current Setting (default) Amendment Setting
Upload Schedule 60 minutes 10 minutes
Log Generation Timeout** 900 seconds @ 15mins 600 seconds @ 10mins

 

The time to generate log every X second must be shorter than or equal to the Upload Schedule time.

 

1.PNG

 

However, there is no recommended setting as it depends on which interval suits the customer environment.

Contributors