Hi all,
I am currently having an issue with the traffic logs on a Fortigate 1500D, and I am out of ideas as to what the root cause is. The Fortigate is currently running 6.0.1 with multiple VDOMs, and it has been configured to send logging messages to a FortiAnalyzer unit running 6.2.2.
It was working fine until around 2 months ago, when it suddenly stopped sending traffic logs to FortiAnalyzer. However, it is still sending the event logs.
The policies are configured to 'log all', and I can see matching traffic if I open the traffic logs and set the location to disk/memory. However, if I view the logs sent to FortiAnalyzer, it will only show traffic that has hit the implicit deny rule.
On the FortiAnalyzer, I can see the event log file under 'Log Browse', however there is nothing for traffic logs, so I assume the Fortigate is at fault.
I have read the Fortinet support documentation and I believe I have covered all of the obvious areas such as checking the connection from the CLI and setting the severity level to information.
The FortiAnalyzer unit is also collecting logs for three other firewalls, and I have compared the working units against this one, and I cannot see any differences.
Does anyone have any advice on how to rectify this problem?
Thank you for your help.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1778 | |
1116 | |
767 | |
447 | |
242 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.