FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
kcheng
Staff & Editor
Staff & Editor
Article Id 283119
Description

This article describes how to retrieve logs for undeployed FortiGate from FortiGate Cloud. 

 

Once FortiGate is undeployed from FortiGate Cloud, the FortiGate Cloud administrator and authorized user will not be able to see the respective device on the asset page. The device list page only shows devices that are deployed under the respective account:

 

Screenshot 2025-12-10 153456.png

 

By default, the undeployed FortiGate is not shown on the asset page, and the historical logs are not visible.

Scope FortiGate Cloud.
Solution

The historical logs for the undeployed FortiGate are associated with an artificial device entry that can be viewed by toggling the view of the 'RMA'd and Undeployed' feature to enable.

 

 From the device list screen, select 'Options' and toggle 'RMA'd and Undeployed' to enable.

Screenshot 2025-12-10 144451.png

Once enabled, it will be possible to view the undeployed FortiGate from the device list page. The serial number of an undeployed device is artificial and does not have any relationship to the original serial number of a real device.

Screenshot 2025-12-10 153734.png


Devices that were undeployed from FortiGate Cloud have a serial number starting with ‘U00’. Devices with a closed RMA that were never undeployed have a serial number starting with ‘R00’.

To access the historical logs, navigate to Analytics -> Log and choose the log type to be viewed.

Screenshot 2025-12-10 154104.png

The logs can be downloaded following the article 'Technical Tip: How to export bulk logs from RMA & Undeployed Devices in FortiGate Cloud'

Note:

For a free FortiGate Cloud account, log retention is only 7 days, while the FortiGate Cloud Premium account has a log retention of 1 year. Logs that exceed the log retention date will be deleted from FortiGate Cloud.

 

If the device was undeployed 14 days ago and had a free FortiGate Cloud account, the logs will be empty.

 

Related articles:

Technical Tip: How to enable FortiCloud logging from CLI

Technical Tip: No VDOM Logs in FortiGate Cloud

Technical Tip: How to view logs on FortiGate Cloud