Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Frosty
Contributor

Possible to use FA100C as a syslog server?

Noticed that in the v4.3.5 release there was a release note about a fix: " 176521: the FortiAnalyzer fails to store generic syslog messages" I assume that this fix now means that you can use an FA as a kind of generic syslog server. My syslog reporting needs are very, very simple (to the point of being almost non-existant) so am wondering whether I can realistically get rid of the dodgy Ubuntu VM that I am currently using for storage of syslog messages. Is anyone here using their FA to store generic syslog stuff? EDIT: I hadn' t noticed that previous thread about problems with 4.3.3 and 4.3.4 ... just read it now ... are people happier with 4.3.5 and, if so, what kind of basic reporting is possible (I would be happy just to be able to view log records in the GUI truth be known).
1 REPLY 1
Frosty
Contributor

Did some testing through the course of today. I' ve been able to direct syslog(514) data from my domain controllers to the FA100C and was also successful in getting our Microsoft UAG portal server to syslog into the FA100C. So I guess that part of my question is answered. Yes, I can syslog to the FA100C. Reporting being virtually non-existent, I would be interested to know whether anyone has developed themselves a custom dataset for reporting on their syslog data. If you have, any chance you could post your custom SQL statements?
Labels
Top Kudoed Authors