Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
robinh007
New Contributor III

Multi-VDOM Syslog Configuration

Hi,

 

Syslog functionality was operating correctly when a single VDOM was in use. However, after enabling multi-VDOM, the syslog configuration now appears exclusively in the Global VDOM mode, making it applicable only to the Global VDOM.

 

In the root VDOM, where all policies, VPN tunnels, and other configurations are present, it is not possible to configure syslog. Attempts to use the "config log syslogd settings" command in the root VDOM were unsuccessful, as the term "syslogd" is not recognized.

 

We are currently running version 7.4.7v. To forward logs, each VDOM needs to have its own separate syslog configuration.

RH007
RH007
1 Solution
Richie_C
Staff
Staff

Hi @robinh007 

 

If I understand your requirement correctly, the following documentation should give you the information you need.

 

https://docs.fortinet.com/document/fortigate/7.6.1/administration-guide/610676/configuring-multiple-...

 

Thanks

Richard 

Take a backup before making any changes

View solution in original post

4 REPLIES 4
Richie_C
Staff
Staff

Hi @robinh007 

 

If I understand your requirement correctly, the following documentation should give you the information you need.

 

https://docs.fortinet.com/document/fortigate/7.6.1/administration-guide/610676/configuring-multiple-...

 

Thanks

Richard 

Take a backup before making any changes
robinh007
New Contributor III

Thank you @Richie_C 

RH007
RH007
robinh007
New Contributor III

Hi @Richie_C 

 

I have a few questions:

If the syslog configuration is set in the Global VDOM, does that same configuration apply to the root and other VDOMs? Ideally, we would like the syslog configuration to function uniformly across all VDOMs. If the syslog configuration is exclusive to the Global VDOM, do we need to enable syslog override in the root and other VDOMs and manually configure the same syslog settings in each VDOM? To establish the same syslog server configuration and IP address in the root and other VDOMs, is it mandatory to enable syslog override in the VDOMs?

RH007
RH007
Richie_C

Hi @robinh007 

 

If every VDOM has the same behavior (syslog server), then there is not a requirement to enable syslog override.  you just need to specify the configuration once in global and it is inherited by all VDOMs'. 

 

In this case the logs are passed transparently to to the root VDOM (management VDOM) and forwarded to the syslog server from there.

 

Thanks

Richard 

Take a backup before making any changes
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors