I have a FortiAnalyzer collecting logs from my entire network. However, I'm encountering an issue with three FortiGate devices that show an active connection and are sending logs to the FAZ. When I attempt to view the Forward Traffic logs on the FortiGate (selecting FAZ as the source) or directly on the FAZ itself, I receive a "No records found" message. Interestingly, when I switch to viewing System events, all logs are visible, leading me to believe that it's not a connection problem but rather a specific issue with Forward Traffic logs not being displayed.
FGT are on 7.2.7
FAZ are on 7.4.1
Hi Please check if same logs showing in fortigate disk/memory ?
try to change below setting on fortigate and test.
config log fortianalyzer settings
set reliable enable
end
Check KB
Thanks
Madhav
Hi msolanki,
Changed to reliable but still not working, and yes I can see the logs on disk/memory.
On the FAZ size, when I try to check the logs on FortiView > Traffic nothing show up, but on the Log View > Traffic I can see the log files on the FAZ, apparently the FAZ is not able to performing the "get" operation to display the logs.
Hi@dzequimassai,
Please review the following article:
Also select only one device and change to realtime and at the same time correlate under the FGT what is Log & Report > Local/Forward traffic.
Best,
Hi Vraev,
The conectivity between the FGTs and the FAZ is alright, I followed the article and still not working.
When I changed the ADOM on the FAZ, changing the type of Security to Fortigate, resolved the problem for one hour, then stop working again
in the fortianalyzer: logs>events> I find various information such as: system events, user events, vpn events, security rating, HA events among others but with respect to "routers events" I cannot locate it. in the fortigate if this information is found in the logs https://vidmate.bid/ .
Hello @dzequimassai ,
Thank you for contacting the Fortinet Forum portal.
Can you please if the device is on HA ? there is a known issue on 7.2.7 to view logs for fortianalyzer ID : 932537
https://docs.fortinet.com/document/fortigate/7.2.7/fortios-release-notes/236526/known-issues
-Also verify if the same forward logs can be seen in fortianalyzer if yes please check the below article :
Best regards,
Manasa.
If you feel the above steps helped resolve the issue, mark the reply as solved so that other customers can get it easily while searching for similar scenarios.
Hi mpeddalla,
The three FGTs are on 7.2.6, and the logs are set to real time, I followed the article, but no matter what time period I select, still nothing show up.
The only time when worked was when I changed the ADOM on the FAZ, changing the type of Security to Fortigate, resolved the problem for one hour, then stop working again
Additionally to all the said above - check that Fortigates do not have log sending filters configured.
show log fortianalyzer filter
Hi Yurisk,
The command return nothing, what leaves to believe that we have no filters, thus sending everything.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.