Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Mohammed-Mustafa
New Contributor III

Pushing logs to AWS Cloud Watch from AWS FortiGate

I'm running into a scenario where I need to push logs to AWS Cloud Watch from FortiGate and from there perform other activities.

4 REPLIES 4
nithincs
Staff
Staff
Mohammed-Mustafa

It does give some thoughts, but I'm still wondering if I can push custom metrics like Memory to CloudWatch?

maxmonterumisi
New Contributor

From Fortiweb support about the same question:
"After checking your query to send the logs to "AWS Cloud Watch", according to the following Amazon document,

https://aws.amazon.com/cloudwatch/features/#:~:text=CloudWatch%20Container%20Insights%20collects%2C%...

Amazon CloudWatch Logs service allows you to collect and store logs from your own application and on-premises resources, which is available in the "Custom logs" category, you can use AWS Systems Manager to install a CloudWatch Agent, or you can use the PutLogData API action to easily publish logs.

Fortiweb supports "Syslog" and "SIEM" servers to store the logs remotely(referring to the attached picture).

For more information regarding this point, please check the "Configuring logging" section in the following document:

https://docs.fortinet.com/document/fortiweb/7.0.10/administration-guide/303842/logging#monitoring_20...

I would suggest checking whether CloudWatch could support getting logs from either Syslog or SIEM, then you may configure fwb to send logs to one of them."
I think it's a truly notable shortcoming not to be able to store WAF logs on CloudWatch for a product that is sold directly on the AWS marketplace.
The only alternative, quite ugly, is to install a syslog, send all the logs there and on the instance with the syslog enable the CloudWatch agent to write them back to CW Logs. But again, it's a bad method.

sb-solutions

I agree, this is a huge limitation, and better integration into cloudwatch for FortiOS products is needed.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors