Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
goudd
New Contributor

FortiGate logs collection and parsing issues

Hi everyone, bear with me as I’m not a network admin, just a security analyst, and I’d like to ask for your help.
I’m receiving FG logs in the log management system we have (Graylog) through Syslog. I cannot configure any of this, I just want to make use of the logs for dashboards and alerts in the log management. The FortiGates that log into Graylog seem to send logs in batches (multiple logs in one message, usually about 65k chars long, last log that would reach the treshold would be incomplete and cut in a random spot). Both Graylog and Syslog don’t know how to deal with this sort of message or how to parse it into singular messages.
Is there a way to configure either FGs to send logs one by one or to make the receiving devices understand these logs? What are your general best practices or have you even encounter this behaviour before? Would sending logs one by one put a big load on the firewall and receivers and also on the network?
Thanks for your opinions and ideas in advance.

https://19216811.cam/ https://1921681001.id/
2 REPLIES 2
AEK
SuperUser
SuperUser

Hi Goudd

I guess you are sending via TCP, that's why such parsing issue.

I hope the below tech tip will help.

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-FortiGate-syslog-via-TCP-and-log-par...

 

AEK
AEK
ndumaj
Staff
Staff
Labels
Top Kudoed Authors