Description
Solution
This article provides a possible solution for the situation where the event log on FortiAnalyzer displays the following message:
Unable to accept logs from Device...... due to internal error, errcode=-1002.
Unable to accept logs from Device...... due to internal error, errcode=-1002.
Solution
This may be due to the processes fortilogd and sqllogd not working correctly. They can be restarted using the following CLI commands.
After restarting the processes the FortiAnalyzer should now operate correctly and receive logs from associated FortiGates.
#diag test app fortilogd 99
#diag test app sqllogd 99
After restarting the processes the FortiAnalyzer should now operate correctly and receive logs from associated FortiGates.