Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
RolandBaumgaertner72
Contributor

Configuring various Syslog Server problem

Hi,


2 weeks ago I configured another syslog server from the CLI and it worked fine. Now I tried the same with the same information on another FG100F and I dont get anything at our local Greylock Server.

>config log syslogd2 setting > get shows me on both sides the same information:

 

FG_MASTER_XXX (setting) # get
status : enable
server : XXX.X.98.58
mode : udp
port : 1514
facility : local7
source-ip :
format : default
priority : default
max-log-rate : 0
interface-select-method: auto


The rule on the FG in the DC is for all the same.

 

What am I missing?

 

Thanks

 

4 REPLIES 4
narunrj
New Contributor

Right now I'm simply looking to get our environment logging to a central location. We have multiple offices and many devices in each office (switches, servers, NAS, SAN, APs, etc...) and other than logging into each device when there is an issue, we don't have a central platform to view logs.

omegle xender
AEK
SuperUser
SuperUser

Hi Roland

I assume your are not wrong with your syslog port 1514 UDP.

Then as first step you may try sniff traffic from both server side and FG side on the same destination port to see if FG is sending anything to server and if server is receiving from FG.

AEK
AEK
RolandBaumgaertner72
Contributor

Hi,

 

I didnt change anything but it works, after trying with diag log test we got traffic on the other side.

 

Can we know when the FG sends logs, is there a shedule?

 

Thanks

 

AEK
SuperUser
SuperUser

As per my knowledge syslog (or at least default config) is sent instantly as the event occurs.

AEK
AEK
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors