Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kinmun
New Contributor II

Analyzer logs to syslog

how do I configure the analyzer such that logs older than 1 months are stored in the syslog server?

i have already configured a syslog server on the analyzer.

 

3 REPLIES 3
kinmun
New Contributor II

currently, I have analyzer to collect the logs after every day.

I understand that there is also forticloud to collect logs n reporting.

but I have yet find any documents to say that i can do the following

1 day logs (disk) -> more than 1 day logs (forticloud or analyzer) -> more than 3 month logs (syslog server)

 

documentation only say either to analyzer/forticloud or multiple syslog server.

every logging solution is discuss seperately but not as a whole solution

L_FTNT
Staff
Staff

If I understood correctly, you would like to be able to configure the following rules for log storage based on the age of the logs

- if age <=1 day, store logs on FGT's local disk

- if 1 day < age  <= 3 months, send logs to FortiAnalyzer/FortiCloud 

- if age > 3 months on FortiAnalyzer/FortiCloud , send logs to syslog.

 

Ling Lu
kinmun
New Contributor II

yes, that is correct.

can it be done through the CLI ??

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors