Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
vireak_roeurn33
New Contributor

FortiGate log send backup to Tape server

Dear Expertise,

 

I would like to ask you regarding backing our Fortigate log to tape is a good way or not? we are using FAZ and our license can support only 5GB per day.

 

Thanks

1 Solution
AEK

Hi

Then I think the 5GB/day limit has nothing to do with archiving or tape. I understand the issue here is not keeping logs for long time but is related to FAZ license for daily log  capacity.

It is recommended to send all logs to FAZ (or SIEM) so the correlation is done properly. So in your case the recommendation is to extend the FAZ license.

If this is not an option for you and you only need to keep logs for traceability then you can forward the FGT logs to a free Linux based syslog server.

AEK

View solution in original post

AEK
12 REPLIES 12
kvsivasakthi
New Contributor II

Hi Virek,

You can tune your logging in firewalls to optimise logging. And you can archive logs into any other severs for 90 days or as per your company policy.

 

Thanks

Siva
Siva
vireak_roeurn33

hi, we have tried to optimize log on firewall by using log filter even tho, that couldn't help

vireak_roeurn33

firewall keep send over 5GB log per day which is exit license limit

AEK
SuperUser
SuperUser

Hi Vireak

 

Usually companies archive logs on tape if a very long retention (several years) is needed.

For some companies this can be required for legal reasons.

 

On FortiAnalyzer you can download the files from menu "Log View > Logs > Log Browse" to send them to tape.
Ref:  https://docs.fortinet.com/document/fortianalyzer/7.6.4/administration-guide/995169/downloading-a-log...

 

You can also use CLI command "execute backup logs ..." to send them to your archive server eventually in order to store them on tape.
Ref:  https://community.fortinet.com/t5/FortiAnalyzer/Technical-Tip-Backup-and-restore-of-FortiAnalyzer-se...

AEK
AEK
vireak_roeurn33

Hi @AEK ,

 

so in case i require to backup log to Tape. Can i configure backup from fortigate to tape or from FAZ to tape?

 

FortiGate -> FAZ -> Tape server
FAZ -> Tape Server (by customize on backup fortigate log to tape server)

 

Am i correct with this workflow?

 

adambomb1219
SuperUser
SuperUser

Do you really need this? Why Tape? Why not a modern SIEM or other product?

vireak_roeurn33

Hi, we have only FAZ and our Fortigate sending the log to FAZ more than 5GB per day, this is the reason why we are seeking idea whether it is a good idea to do it or not.

 

AEK

Hi

Then I think the 5GB/day limit has nothing to do with archiving or tape. I understand the issue here is not keeping logs for long time but is related to FAZ license for daily log  capacity.

It is recommended to send all logs to FAZ (or SIEM) so the correlation is done properly. So in your case the recommendation is to extend the FAZ license.

If this is not an option for you and you only need to keep logs for traceability then you can forward the FGT logs to a free Linux based syslog server.

AEK
AEK
vireak_roeurn33

Hi AEK,

 

Thank you for your recommendation. I understand it now.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors