FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
AnthonyH
Staff
Staff
Article Id 383217
Description This article describes a known issue when trying to import FortiGate Cloud Logs labelled with the extension type 'log.gz' where the error 'Invalid Log File' or 'Internal Error' causes a failure in importing logs into FortiAnalyzer Cloud.
Scope FortiGate Cloud, FortiAnalyzer Cloud.
Solution

The issue:

 

Downloading Raw logs requires a subscription to FortiGate Cloud to download which can be found under https://login.forticloud.com -> Services -> FortiGate Cloud -> Analytics -> Raw logs.

 

The types of logs that can be exported in the 'log.gz' format will be available here.

 

For example: FGVM01XXXXXXXXX_tlog_20250317-1549-20250320-0757.log.gz

 

The information contained in a tlog (traffic logs) will look like the following:

 

date=2025-03-19 time=13:17:58 eventtime=1742404677400430149 tz="-0400" logid="0000000013" type="traffic" subtype="forward" level="notice" vd="root" srcip=X.X.X.X srcport=65436 srcintf="LAN" srcintfrole="lan" dstip=8.8.8.8 dstport=53 dstintf="wan1" dstintfrole="wan" srccountry="Reserved" dstinetsvc="Google-DNS" dstcountry="United States" dstregion="California" dstcity="Mountain View" dstreputation=5 sessionid=8268497 proto=17 action="accept" policyid=1 policytype="policy" poluuid="ac47435a-3c92-51ee-4ce4-3ab6abb2b65a" policyname="INTERNET-VLAN" service="Google-DNS" trandisp="snat" transip=X.X.X.X transport=65436 appcat="unscanned" duration=181 sentbyte=56 rcvdbyte=132 sentpkt=1 rcvdpkt=1 vwlid=0 srchwvendor="MSI" devtype="Router" osname="Unknown" mastersrcmac="XX:XX:XX:XX:XX:XX" srcmac="XX:XX:XX:XX:XX:XX" srcserver=0

 

Now, when importing the log.gz file into FortiAnalyzer Cloud under https://login.forticloud.com -> Services -> FortiAnalyzer Cloud -> Log View -> Log Browse -> Import, the following errors may be observed:

 

Internal_error.PNG

 

Invalid_log_file.PNG

 

The problem is due to the exported logs from FortiGate Cloud where 'devid' or 'itime' is not present in the raw logs. In addition, the log file name should be in the following naming scheme: devid.<t>log.log/txt/csv 

 

The workaround:

 

  1. Export the logs from FortiGate Cloud.
  2. Extract the file and modify the contents to add 'devid' and 'itime'.
  • For windows, 7Zip can be used to extract the file.

 

Text_file.png

 

  1. Save the file with the following format: devid.<t>log.log/txt/csv
  2. Import it into FortiAnalyzer Cloud using 'Taken From Imported File'.

 

import_log_file_success.PNG