Hello,
For syslog configuration in FAZ, why is necessary configure system syslog and system aggregation-client?
What is their relation?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
configure system syslog ... for sending local event logs
system aggregation-client (5.4 or earlier) ... for forwarding logs from another device
Hi Chall,
When I configured just system syslog I couldn't see traffic through sniffer, just i saw traffic when i configured system aggregation-client, why did happened it?
aggregation-client is intended to forward logs received by other logging devices such FGT. system syslog is like send local FAZ event logs to a systlog device. In your case like FAZ event log may not happen so often as other logs from other devices.
Also it maybe need additional tuning on severity and etc from cli: config sys locallog syslogd filter config sys locallog syslogd settings
Thanks everyone for your answers!
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1696 | |
1091 | |
752 | |
446 | |
228 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.