This article covers a basic setup steps allowing FortiAnalyzer (FAZ) to accept FortiClients (FCT) logs.
FAZ collects FCT logs into FortiClient ADOM. They logs are stored under the EMS's serial number managing the FortiClients.
And in order to do so the EMS needs to be registered at the FAZ.
FAZ collects FCT logs into FortiClient ADOM. They are stored under the EMS serial number managing these FortiClients. In order to do so the EMS needs to be registered at the FAZ.
[ol]
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello,
I followed your steps to add EMS to FAZ. Is it normal if EMS status in FAZ showing "Log Status Down" and Real-Time have red circle?
Thanks.
Hi there,
It depends on your "upload schedule" on EMS profile setting. Currently if one device didn't receive logs for 15min, it will be marked as "Log Status Down".
regards,
hz
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1714 | |
1093 | |
752 | |
447 | |
232 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.