Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
boggiu
New Contributor

No entries found in all log

Hi all, Why don' t see the log even if checked ? Thank you in advance
ab
ab
21 REPLIES 21
boggiu
New Contributor

Hi neonbit, where i can enable traffic log in forti v5.0 ?
ab
ab
emnoc
Esteemed Contributor III

back to the rem-syslog server, you can do a diag snifffer packet " interface-name" ' port 15000' and see if any traffic is sourced from the firewall to the host you can also do that on the server quite easily. Make sure logging is enabled If you see traffic, than check the unix facilities local7 o kill -HUP the syslogd daemon. Make sure the process can write to the file as a permission check ( assuming unix ) chmod the file to 777 as temp and see if files are written. If you see syslog data write than you know it' s a daemon write-accesss/ownership issue. btw splunk is good

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
boggiu
New Contributor

Hi AtiT and emnoc, I tried sniffer port 1500 on fortigate ip and there are no ip packets in this port, any idea ? Thank you for important help. (syslog server configured on global VDOM, need configure this in all VDOM ? )
ab
ab
boggiu
New Contributor

Any suggestions? Atit, you can show your setting for syslog server (config log syslogd setting ..) In " source-ip" you have an address ? Thank you in advance
ab
ab
AtiT
Valued Contributor

Hi, my settings are: LAB_LUX # config global LAB_LUX (global) # get log syslogd setting status : enable server : 192.168.222.111 reliable : disable port : 15000 csv : disable facility : local7 source-ip : 0.0.0.0 LAB_LUX (global) #

AtiT

AtiT
emnoc
Esteemed Contributor III

OP, are 100% logging enabled and did you sniffer on the fortigate or the remote syslog server ? Can you ping the log host 192.168.222.111 ?

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
boggiu
New Contributor

Yes,I can ping my syslog server (10.0.14.94), Sniffer is on syslog server (I can ping fortinet on syslog server) and a try filter on port 15000(port for syslog in a configuration). I think fortinet not send any packet on this port.
ab
ab
emnoc
Esteemed Contributor III

Now I' m really confused, we have 2 screen shots 10.0.17 and 10.0.14 .94 which is it? Now to diagnose this, we need you double check port and ip_address. And provide the following; show log syslogd filter show log syslogd setting show log memory Next, set up a sniffer to list on the port that you have syslog running on < 15000 > ???? And then execute a logging event like a failed admin login or even easier execute a diag test log You should see a syslog packet generated and sent to the syslog. i.e FG200B1G02811942 # diag log test generating a system event message with level - warning generating an infected virus message with level - warning generating a blocked virus message with level - warning generating a URL block message with level - warning generating a DLP message with level - warning generating an attack detection message with level - warning generating an application control IM message with level - information generating an application control VOIP message with level - information generating an antispam message with level - notification generating an allowed traffic message with level - notice generating a wanopt traffic log message with level - notification generating a HA event message with level - warning

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
boggiu
New Contributor

Hi, sorry I change IP address of syslog server ... I attached all command requested, view log but seems fortinet not send log at port 1500. I do not understand ... Thank you for support..
ab
ab
boggiu
New Contributor

Emnoc, i have 3 vdom, in global setting set syslog server ... in vdom that i want to see log i can' t set syslog server, could this be the problem?
ab
ab
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors