Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
davill
New Contributor

Fortiweb Cloud logs

We want to send the attack or traffic logs from the fortiweb cloud to a fortianalyzer.

I have configured the logging part but I do not see that the Fortianalyzer receives this traffic.

Does anyone know how?

3 REPLIES 3
Debbie_FTNT
Staff
Staff

Hey davill,

I'm not terribly familiar with FortiWebCloud, but I would start by treating this like any other connection issue:

- verify traffic is being sent by FortiWebCloud (it should use port 514)

- verify FortiAnalyzer is receiving this traffic (diag sniffer command works on FortiAnalyzer)

-> if FortiAnalyzer is receiving the traffic, start digging there. Are ADOMs enabled, is the FortiWebCloud serial number added as a device, etc

-> if FortiWebCloud is failing to send the traffic, investigate there

-> if FortiWebCloud is sending, but FortiAnalyzer is not receiving anything, check the network(s) in between and determine where the traffic might be dropped

 

If the issue is with either FortiWebCloud not sending, or FortiAnalyzer receiving but not doing anything with it, you might reach out to Fortinet Technical Support for further assistance in troubleshooting the matter.

+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++
davill
New Contributor

the problem is that FortiWeb Cloud is not like a FortiWeb on premise, I don't have access to the console to apply sniffer or a debug.

NunoLour
New Contributor II

Btw, FortiAnalyzer 7.4 already has support for FortiWeb-Cloud attack logs 

 

Check it on the documentation :

https://docs.fortinet.com/document/fortianalyzer/7.4.0/new-features/352644/fortianalyzer-supports-fo...

 

Labels
Top Kudoed Authors