Hello Fortinet Support,
We are facing an issue where EMS logs are not being ingested into Forti Analyzer. At present, only FortiClient logs are visible, but EMS server activity/logs are not showing up.
Details:
Product: Forti Analyzer & FortiClient EMS
Issue: EMS logs not ingesting/forwarding to Forti Analyzer
Observed: Only FortiClient logs are displayed
Expected: Both FortiClient and EMS logs should be ingested for full visibility
Request:
Could you please assist us in troubleshooting and resolving this? If any specific configuration or version requirements are needed for EMS log forwarding, kindly provide guidance.
Solved! Go to Solution.
Hi Hamza
Did you configure log forward to FAZ on your EMS? Can you share a screenshot of the config?
Did you authorize EMS on FAZ?
You can also use "diag sniffer" on FAZ to check if logs are received from EMS.
Hi Hamza
Did you configure log forward to FAZ on your EMS? Can you share a screenshot of the config?
Did you authorize EMS on FAZ?
You can also use "diag sniffer" on FAZ to check if logs are received from EMS.
Please check the attach configuration snap
The config from EMS side looks fine.
What about FAZ side?
Double-check that EMS log forwarding to FortiAnalyzer is enabled and that both products are on compatible builds. You may also need to verify the EMS connector settings under Device Manager. Fortinet docs list the exact steps.
User | Count |
---|---|
2626 | |
1400 | |
810 | |
672 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.