Hi all,
i've got an infrastructure of cluster fortigate running 7.4.5 managed by fortimanager. One of this cluster is in the headquarter all the others are branch offices. All of the clusters send logs to the fortianalyzer and all the branch offices send also syslog to a syslog collector behind the headquarter cluster.
When looking in the fortianalyzer pointing the headquarter cluster i can see all the branch offices send the events via syslog, but if i point the branch offices to see the events exit from the firewall i can see them only from one branch office and all the others are not showed. I'll past the config from the one i can see and from the other that not. To me they seems the same
This is the one not working:
fw-xxxxx-xxxxxxxxxxxx-o~-01 (setting) # get
resolve-ip : disable
resolve-port : enable
log-user-in-upper : disable
fwpolicy-implicit-log: enable
fwpolicy6-implicit-log: disable
extended-log : disable
local-in-allow : disable
local-in-deny-unicast: disable
local-in-deny-broadcast: disable
local-out : enable
local-out-ioc-detection: enable
daemon-log : disable
neighbor-event : disable
brief-traffic-format: disable
user-anonymize : disable
expolicy-implicit-log: disable
log-policy-comment : disable
faz-override : disable
syslog-override : disable
rest-api-set : disable
rest-api-get : disable
long-live-session-stat: enable
custom-log-fields :
This is the one that working
fw-xxxxx-xxxxxxxxxx~-01 (setting) # get
resolve-ip : disable
resolve-port : enable
log-user-in-upper : disable
fwpolicy-implicit-log: disable
fwpolicy6-implicit-log: disable
extended-log : disable
local-in-allow : disable
local-in-deny-unicast: disable
local-in-deny-broadcast: disable
local-out : enable
local-out-ioc-detection: enable
daemon-log : disable
neighbor-event : disable
brief-traffic-format: disable
user-anonymize : disable
expolicy-implicit-log: disable
log-policy-comment : disable
faz-override : disable
syslog-override : disable
rest-api-set : disable
rest-api-get : disable
long-live-session-stat: enable
custom-log-fields :
Please help
Thanks in advance
hi,
so if i understand correctly, you have multiple firewalls/clusters in hq and remote locations and all send logs to fortianalyzer and the remote ones send also to a syslog ?
one fortigate/cluster is sending logs to the syslog but the others dont ?
can you do a , show full log syslogd setting on the one that works and one that doesnt ?
Created on ‎10-13-2025 12:06 AM Edited on ‎10-13-2025 12:08 AM
Hi, i'm sorry. The problem it's seem like all of the branch office execpt one don't log the syslog traffic that originated from the gateway itself, but all the logging are working fine
I will try with an image to try to explain this issue, sorry for my bad english
hi,
can you share your config/output regarding syslog and fortianalyzer settings on the working branch firewall and from one which is not working?
the commands would be:
show log syslogd setting / show log syslogd filter
show log fortianalyzer setting / show log fortianalyzer filter
Hi, thank you for your reply.
Working one
fw-xxxxx-le-~-01 (global) # show log syslogd setting
config log syslogd setting
set status enable
set server "x.y.13.250"
end
fw-xxxxx-le-~-01 (global) # show log syslogd filter
config log syslogd filter
end
fw-xxxxx-le-~-01 (global) #
fw-xxxxx-le-~-01 (global) # show log fortianalyzer setting
config log fortianalyzer setting
set status enable
set server "x.y.10.35"
set serial "FAZ3HGTA-" "FAZ3HGTA-"
set ssl-min-proto-version TLSv1-3
set upload-option realtime
set reliable enable
end
fw-xxxxx-le-~-01 (global) # show log fortianalyzer filter
config log fortianalyzer filter
end
Not working one
fw-xxxxx-va-o~-01 (global) # show log syslogd setting
config log syslogd setting
set status enable
set server "x.y.13.250"
end
fw-xxxxx-va-o~-01 (global) # show log syslogd filter
config log syslogd filter
end
fw-xxxxx-va-o~-01 (global) #
fw-xxxxx-va-o~-01 (global) # show log fortianalyzer setting
config log fortianalyzer setting
set status enable
set server "x.y.10.35"
set serial "FAZ3HGTA-" "FAZ3HGTA-"
set ssl-min-proto-version TLSv1-3
set upload-option realtime
set reliable enable
end
fw-xxxxx-va-o~-01 (global) # show log fortianalyzer filter
config log fortianalyzer filter
end
the config look identical so it should work for the other as well.
I assume that the devices were authorized in FAZ and they are visible in either root ADOM or any other.
have a look at https://community.fortinet.com/t5/FortiAnalyzer/Troubleshooting-Tip-No-logs-received-on-FortiAnalyze... and try to tshoot the issue
Yes thery are identical and the strange thing is that only syslog it's not visible. I will look in sk for troubleshooting. Thank you
can you simplify the query or problem.
Is the remote branches not sending logs to Fortianalyzer and sending to syslog server ?
Created on ‎10-13-2025 12:00 AM Edited on ‎10-13-2025 12:00 AM
All of them sending log correctly as i can see from fortianalyzer selecting the head quarter. If on fortianalyzer i select the branch office to see the log i can see only from one branch office not for the others. I hope it's more clear now
| User | Count |
|---|---|
| 2712 | |
| 1416 | |
| 810 | |
| 733 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.