Hi Fortinet Community,
When I try to get logs to FortiAnalyzer via EMS and ems endpoints, I see that the endpoint sends logs directly to FortiAnalyzer.
Logically I thought that it sends it to the analyzer on the EMS, but I realized that this is not the case.
How exactly does FortiAnalyzer and FortiClient EMS log collection logic work?
Best Regards,
İsmail Ürek
Hi Ismail
For EMS you configure it in the "Log Settings".
For the client you configure it from on the "System Settings" endpoint profile.
User | Count |
---|---|
2549 | |
1356 | |
795 | |
646 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.