Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mmarchetti
Visitor

Log not shown as expected

Hi all,

i've got an infrastructure of cluster fortigate running 7.4.5 managed by fortimanager. One of this cluster is in the headquarter all the others are branch offices. All of the clusters send logs to the fortianalyzer and all the branch offices send also syslog to a syslog collector behind the headquarter cluster.

 

When looking in the fortianalyzer pointing the headquarter cluster i can see all the branch offices send the events via syslog, but if i point the branch offices to see the events exit from the firewall i can see them only from one branch office and all the others are not showed. I'll past the config from the one i can see and from the other that not. To me they seems the same

This is the one not working:

fw-xxxxx-xxxxxxxxxxxx-o~-01 (setting) # get
resolve-ip : disable
resolve-port : enable
log-user-in-upper : disable
fwpolicy-implicit-log: enable
fwpolicy6-implicit-log: disable
extended-log : disable
local-in-allow : disable
local-in-deny-unicast: disable
local-in-deny-broadcast: disable
local-out : enable
local-out-ioc-detection: enable
daemon-log : disable
neighbor-event : disable
brief-traffic-format: disable
user-anonymize : disable
expolicy-implicit-log: disable
log-policy-comment : disable
faz-override : disable
syslog-override : disable
rest-api-set : disable
rest-api-get : disable
long-live-session-stat: enable
custom-log-fields :

 

This is the one that working

fw-xxxxx-xxxxxxxxxx~-01 (setting) # get
resolve-ip : disable
resolve-port : enable
log-user-in-upper : disable
fwpolicy-implicit-log: disable
fwpolicy6-implicit-log: disable
extended-log : disable
local-in-allow : disable
local-in-deny-unicast: disable
local-in-deny-broadcast: disable
local-out : enable
local-out-ioc-detection: enable
daemon-log : disable
neighbor-event : disable
brief-traffic-format: disable
user-anonymize : disable
expolicy-implicit-log: disable
log-policy-comment : disable
faz-override : disable
syslog-override : disable
rest-api-set : disable
rest-api-get : disable
long-live-session-stat: enable
custom-log-fields :

 

Please help

 

Thanks in advance

1 REPLY 1
funkylicious
SuperUser
SuperUser

hi,

so if i understand correctly, you have multiple firewalls/clusters in hq and remote locations and all send logs to fortianalyzer and the remote ones send also to a syslog ?

one fortigate/cluster is sending logs to the syslog but the others dont ?

can you do a , show full log syslogd setting on the one that works and one that doesnt ?

"jack of all trades, master of none"
"jack of all trades, master of none"
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors