FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Article Id 295314

This article explains how to stop sending logs to FortiAnalyzer in a specific VDOM context.

  • In normal conditions, while enabling global log configuration to send log to FortiAnalyzer individual, VDOM is not allowed to edit/update log setting under VDOM context.
  • In a multiple VDOM environment, all VDOM log records will be sent to FortiAnalyzer via management VDOM.


There will be situations where one or two special VDOMS do not require sending logs to other logging devices.

Scope FortiGate v7.0 and above.

1. Check the system's global log setting and VDOM information. Global log setting enabled send log to FortiAnalyzer.

2024-01-22 13_23_10-FortiGate - FGVM01TM21001418 — Mozilla Firefox.png



Individual VDOM is populated with log settings configured in a global context. No VDOM log settings edit is allowed (settings greyed out) while referencing to global log settings.


2024-01-22 13_33_25-FortiGate - FGVM01TM21001418 — Mozilla Firefox.png


  1.  Enable the 'faz-override' option. While 'faz-overide' is disabled, no edit is allowed within the VDOM context.




To be able to edit the VDOM context log settings, the 'faz-override' option needs to be enabled.


2024-01-22 13_52_08-FortiGate - FGVM01TM21001418 — Mozilla Firefox.png


Once the 'faz-override' option is enabled, the GUI log setting under the VDOM context is allowed for editing/updating.


2024-01-22 13_57_02-FortiGate - FGVM01TM21001418 — Mozilla Firefox.png


  1. Disable 'send logs to FortiAnalyzer/FortiManager' on Remote logging and Archiving settings to stop sending logs within the VDOM context. Select the 'Disabled' option.


2024-01-22 14_01_53-FortiGate - FGVM01TM21001418 — Mozilla Firefox.png




2024-01-22 14_05_43-FortiGate - FGVM01TM21001418 — Mozilla Firefox.png