Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
badrgb
New Contributor III

How to compare Fortigate logs sent and the logs received by the FortiAnalyzer?

Hello,

My question is how can I compare the logs sent from a Gortigate FW in a specific date and the logs received if the FortiAnalyzer in the same date?

 

Can I do an extract for the "Forwardin logs" in the FW and compare it with an extract from the FortiAnalyzer for the same date? and if I have the same number of line, I will judge that they're no problem in sending/receiving logs?

 

or they are a better way?

 

thank you

2 REPLIES 2
Markus_M
Staff
Staff

Hi badrgb,

 

you could export the logs from the FortiAnalyzer directly and go to the FortiGate and export the logs from there, right after selecting to get the logs from disk/memory (upper right of the screen there is a selector for this).

 

Best regards,

 

Markus

badrgb
New Contributor III

Thank you @Markus_M for your reply,

I have the same Idea but I want a confirmation from experts :) , and look if they are a better way (I have a file with over 400000 lines from the fortigate).

 

Thank you for confirming my idea.

Labels
Top Kudoed Authors