We're sending all logs from FAZ running 7.4.6 to an external log collector, but we want to not send some traffic, such as NetFlow over tcp port 2055. Under Systems Settings > Advanced, there is a Log Forwarding tab where we've defined where the messages are being forwarded to, and within this area, there is a section called "Log Forwarding Filters." I've been looking into the "Enable Exclusions" section, where it's possible to select a field called "Destination Port (dstport)," but it doesn't appear to be possible that the actual port number can be defined. Can this be done? If so, can anyone offer guidance for accomplishing this? Thank you.
Hello albaker1,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hello,
We are still looking for an answer to your question.
We will come back to you ASAP.
Thanks,
Hello albaker1,
I found this solution. Can you tell me if it helps, please?
To exclude logs based on a specific destination port, such as TCP port 2055, you can configure log forwarding filters on FortiAnalyzer. Here’s how you can do it:
This configuration will ensure that logs with the specified destination port are not forwarded to the external log collector.
User | Count |
---|---|
2546 | |
1354 | |
795 | |
643 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.