Hello everyone
I have two virtual Fortigates (one in Azure, one on ESXi). Both of them have local disks and both are configured to send the logs to a Fortianalyzer. Both Fortigates are on 6.4.9.
When enabling disk logging (config log disk setting - set status enable) nothing changes - I get the logs to the Fortianalyzer, but I don't have any local logs.
Is that a bug or is this intended? Can't I have the same logs on both, local and send remotly?
Thanks for your input
Best regards
scheuri
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello,
It should be possible to log to disk and FortiAnalyzer simultaneously.
Please make sure that you select disk in the logging section (top right corner next to details), alternatively you may consider to view disk logs in CLI:
On top of abarushka's excellent suggestion are you sure the VMs have a log disk configured? It would be datadrive.vmdk for the ESXi deployment.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.