Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Unable to LOG anything to a syslog server

Hello, I' m getting mad. I' m unable to send any log messages to a syslog server installed in a PC. The syslog server works, but the Fortigate doesn' t send anything to it. It' s a Fortigate 200B, firm 4.0 build 0178 (MR1). I think everything is configured as it should, interfaces are set log enable, and policy rules I would like to log are log allowed. But it doesn' t work. I' m getting mad. Do I need to reset the firewall after configure logging ? Can I restart log service only ? Firmware bug ? Thanks
17 REPLIES 17
hidayet
New Contributor II

Hi Silvio, Check the link below; http://docs.forticare.com/fgt/techdocs/fortigate-logging_reporting.pdf
http://www.hidayetaltun.com
http://www.hidayetaltun.com
Not applicable

Hi hidayet, I followed that guide some days ago to configure logging, but my problems remain. There must be something I missed, but I can´t find what. The syslog server has the same IP C class, and there isn' t any firewall betweeen both. I can´t understand why I don' t receive logs. I think I need some help. Thanks
hidayet
New Contributor II

If documentation is done by setting up and running
http://www.hidayetaltun.com
http://www.hidayetaltun.com
rwpatterson
Valued Contributor III

What firmware is on the FAZ?

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

I am trying to send log messages to a syslog server installed on a PC. It' s working properly , but no messages from the FGT
jmac
New Contributor

Use the FortiGate packet sniffer to verify syslog output: diag sniff packet any " udp and port 514" Verify the source address (FortiGate interface IP) and destination IP. If no packets, possibly a FortiGate issue or configuration (verify default syslog port in FortiGate). If packets, then a syslog receiver issue (verify client IP/port/firewall/etc).
Not applicable

Hi again, I tried diag sniff packet any " udp and port 514" and no packets appear, so no traffic comes out ot any interface in that port. get log syslogd setting confirms port 514. I don' t know what to do. Thanks
red_adair
New Contributor III

running sniffer and do a # diagnose log test Any output ? Did you enable " Event Logs" and Login/Logout ? This is the most trivial case to generate a Logentry. I assume you have Syslog-Server IP entered correctly ? in GUI or via # config log syslogd setting -R.
Not applicable

I ran that diagnose log test in a ssh window while running diag sniff packet any " udp and port 514" in other ssh window, and no packets appeared in this window after the first command executing, so I think something happens with my Fortigate. Event logs are all enabled, and the IP is correctly configured. But I can see no packets come out of any interface, even with diagnose log test. Thanks
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors