how do I configure the analyzer such that logs older than 1 months are stored in the syslog server?
i have already configured a syslog server on the analyzer.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
currently, I have analyzer to collect the logs after every day.
I understand that there is also forticloud to collect logs n reporting.
but I have yet find any documents to say that i can do the following
1 day logs (disk) -> more than 1 day logs (forticloud or analyzer) -> more than 3 month logs (syslog server)
documentation only say either to analyzer/forticloud or multiple syslog server.
every logging solution is discuss seperately but not as a whole solution
If I understood correctly, you would like to be able to configure the following rules for log storage based on the age of the logs
- if age <=1 day, store logs on FGT's local disk
- if 1 day < age <= 3 months, send logs to FortiAnalyzer/FortiCloud
- if age > 3 months on FortiAnalyzer/FortiCloud , send logs to syslog.
yes, that is correct.
can it be done through the CLI ??
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.