Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
LTC_FAZ
New Contributor

Log aggregation from FAZ client to server fails

Hi,

 

1. Using log aggregation authorization fails. On the manual page 171 (http://docs.fortinet.com/...inistration-Guide.pdf) . I can seet that manual says that we must configure password under FAZ server "config system aggregation-service" which is the same as on FAZ client. But there are no such commands available in the CLI. In the dashboard alert messages I can see alerts that log aggregation failed because of bad "auth method". How to enable password command? 2. I tried also with other option which is more granular - Fetcher management (page 173.). I have configured both sides with identical passwords and users, but when I press fetch now, other side does not receive request (also auth failed), and it can not be approved manually. I suppose that request could not be successful because log aggregation is not configured first of all.

 

Maybe some suggestions about the problem?

 

Regards,

6 REPLIES 6
scao_FTNT
Staff
Staff

5.2 or 5.4 FAZ? 5.4 FAZ changed design and will use system settings admin user for client to authenticate (so no need to config password on server side but client side need to configure with correct server side admin user/pass)

 

Thanks

 

Simon

Mikael_A
New Contributor II

Got the same issue. Interested if there is a solution.

scao_FTNT

Hi, Mikael, is your issue also for 5.4 FAZ aggregate mode? is both client and server running on 5.4 and re-configured admin user/password on client?

 

Thanks

 

Simon

Mikael_A
New Contributor II

Hi Simon! Yeah, it is.

 

Running 2 VM:s that are using 5.4 software. One in Collector Mode and one is in Analyze mode.

I tried following a guide to the best of my abilities. But it was for 5.2 so some things have changed.

However, let me see if I can give you as much information as possible.

 

The FG that is acting as the device is only added in the Collector FAZ.

On the Collector I´ve setup a connection to the Analyzer under the Log Forwarding option under settings.

Using "Enable Log Aggregation" and a User and password is set.

 

Obviously I need to configure that on the Analyzer as well but the CLI command that did it for 5.2 doesn´t seem to be present in 5.4 How do I configure the Analyzer with the username and password?

 

 

scao_FTNT

How do I configure the Analyzer with the username and password?

   -- on FAZ side, you need to configure the normal super_user profile admin user (same as the one you created for GUI/CLI login) and collector/client is to use this admin user for aggregate login in 5.4

 

Thanks

 

Simon

sgao_FTNT

Hi LTC_FAZ,

 

For the #2 issue (Fetcher Management), it is independent

 - you need setup a administrator (Standard or Super User) on FAZ Fetch server, 

 - then configure this user/pass on fetch client profile

 

Note: accessible devices will be limited in assigned ADOMs

 

Regards,

Shawn

Labels
Top Kudoed Authors