- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
FortiAnalyzer DNS logs No record found.
Hello,
I am currently facing an issue with my FortiAnalyzer when trying to view DNS logs from my FortiGate. Specifically, when I navigate to the FortiView > Traffic > DNS Logs section in FortiAnalyzer and search for DNS activity, the result always shows "No record found", even though DNS traffic is expected to be logged.
Setup Details:
- Configuration:
- FortiGate is configured to forward logs to FortiAnalyzer.
- Other logs (e.g., traffic logs, event logs) are appearing correctly in FortiAnalyzer.
- Labels:
-
FortiAnalyzer
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Ninja_03092 ,
First of all, make sure that there is DNS traffic passing through your FortiGate.
Secondly, please make sure that the firewall policy allowing this DNS traffic flow has Logging enabled.
Jerry
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
yes we have it
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can you share the firewall policy configurations? And do you have any Hit Count for this firewall policy in the GUI?
Jerry
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @Ninja_03092 ,
Check if you can see any DNS logs recorded in Fortigate, Log&Report >> Security events >> DNS query.. If yes, you can check if the firewall policy enables logging.
Thank you.
ametkola
