Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jlozen
New Contributor

Traffic logs no longer making it into FAZ

One of our FortiWiFi 60D units running firmware version 5.2 is having a bit of an issue with traffic logging. It seems to work fine on the local device, but the last day any traffic logs made it into FAZ was August 4th (11 days ago). Other current log events show up fine, such as system performance statistic events. So connectivity is fine between the device and FAZ. Has anyone else run into any problems with not all logs making it into FAZ? I know there seem to be somewhat random issues with many different operations between devices using the 5.2 firmware and FAZ in general. Our FAZ is running firmware v5.0-build4037 131010 (GA) it' s an AWS instance so i can' t update the firmware or i' d have tried that already. I was hoping someone else might have a couple things I could try and hopefully get everything working again, since it was working fine before the 4th. To my knowledge there haven' t been any configuration changes...
5 REPLIES 5
scao_FTNT
Staff
Staff

Hi, jlozen, v5.0-build4037 131010 (GA), from its build timestamps, this build is old and FGT 5.2 log is supported from 5.0.7 (and 5.2.0) Thanks Simon
jlozen
New Contributor

I realize the version mismatches could be causing issues, but it was working fine after being updated the few weeks before the 4th, and I have more than 30 other devices all on 5.2 firmware working fine. Everything seems to be in order on the device as compared to the other working devices. I guess it might be time to open a ticket...
netmin
Contributor II

In a professional support organization, the very first thing you will be told is very likely, to upgrade to a compatible software version. Incompatible versions may or may not work but can' t usually be supported for the same obvious reason - they are not 100% compatible.
Brady_R__Houser
New Contributor

Did you check to see if your remote FortiGate is still listed as an authorized device? If so can you have it do a query of it' s logs? I also had an issue where the logging was turned off on the remote FortiGate. After turning it on it started to log correctly to the FortiAnalyzer. Can you view the logs on the remote unit directly?
jlozen
New Contributor

Thanks all for the replies. I got it working again by changing the filter level and then changing it back... not sure why that worked, but it did. Everything seems to be working just fine now. The commands I used were
 config log fortianalyzer filer
     set severity warning
 end
 config log fortianalyzer filter
     set severity notification
 end
 
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors