Created on
12-17-2025
01:25 AM
Edited on
12-17-2025
05:44 AM
By
Stephen_G
| Description | This article describes an issue where it is not possible to disable FortiAnalyzer logging, as the option to do so is greyed out. |
| Scope | All FortiGates with Security Fabric enabled, and when configured with FortiAnalyzer logging. |
| Solution |
In a scenario where the FortiGate has been enabled with Security Fabric, it is not possible to disable a previously enabled FortiAnalyzer, even if the FortiAnalyzer device has been decommissioned or is otherwise unavailable.
The option to disable FortiAnalyzer will be greyed out as shown:
Attempting to remove (unset) the FortiAnalyzer via the CLI fails with an error (as below), however, this also gives a clue to the reason and also the solution:
The reason for this is that the Security Fabric requires at least one active logging destination.
Therefore, this issue can be resolved by enabling FortiGate Cloud logging to satisfy the Security Fabric requirement.
To configure cloud logging in the GUI:
By default, the settings for FortiAnalyzer logging are synchronized between all FortiGate in the Security Fabric.
To disable the automatic synchronization of these settings, use the following CLI command:
config system csf
set configuration-sync local end
Related documents: Technical Tip: The impact of 'set configuration-sync local' on the Security Fabric |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.