- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Fortigate Syslog Timer
Hi All,
I'm trying to find out how to configure our FG100D (6.2.14-FW-build1364-230411) to send to our Syslog Server (ELK) just every 5 mins. There is no option in the WebUI or even in the CLI to configure this. Is there any way to do this? All I can see is in the FortiAnalyzer option.
Thank you.
Oliver
Solved! Go to Solution.
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @olivern4 ,
Syslog is an instant protocol, so unlike FortiAnalyzer, there is no store-and-forward option on the FortiGate.
NSE 4-5-6-7 OT Sec - ENT FW
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Oliver,
You can get Fortianalyzer/Fortianalyzer cloud license and then configure that on the Fortigate to send logs to Fortianalyzer every 5 minutes.
But you cannot use ELK server ip to configure Fortianalyzer, because when you configure Fortianalyzer it will be configured in the security fabric, which uses separate daemon/ports to forward logs to FortiAnalyzer.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @olivern4 ,
Syslog is an instant protocol, so unlike FortiAnalyzer, there is no store-and-forward option on the FortiGate.
NSE 4-5-6-7 OT Sec - ENT FW
Created on ‎08-19-2024 05:02 AM Edited on ‎08-19-2024 05:07 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @ozkanaltas
Thank you for the response.
Meaning there is no way to do this? Okay. Can I just use the FortiAnalyzer option instead as the Syslog? I will just add the IP address of the ELK server right?
Thank you.
Oliver
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Oliver,
You can get Fortianalyzer/Fortianalyzer cloud license and then configure that on the Fortigate to send logs to Fortianalyzer every 5 minutes.
But you cannot use ELK server ip to configure Fortianalyzer, because when you configure Fortianalyzer it will be configured in the security fabric, which uses separate daemon/ports to forward logs to FortiAnalyzer.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @SonaMuvv
Thank you.
Oliver
