Helpful ReplyHot!Logging to multiple Syslog servers VDOM

Author
jonathanaxford
New Member
  • Total Posts : 4
  • Scores: 0
  • Reward points: 0
  • Joined: 2016/08/24 00:27:00
  • Status: offline
2016/08/24 00:41:50 (permalink)
0

Logging to multiple Syslog servers VDOM

Hi All, 
 
Fortigate 60D v5.2.4(Build688)
 
I've had a bit of a google and it appears it should be possible to setup my VDOMs to log to multiple Syslog servers, but I am struggling to find out how to get this working. 
I have overridden the global syslog settings to allow me to log per VDOM and this is working. Under the global config I get the option to configure syslogd, syslogd2 and syslogd3, but under the VDOM, I only get the option for syslogd. 
 
VDOM options:
 
FIREWALL (root) # config log
custom-field Configure custom log fields.
eventfilter Configure log event filters.
fortianalyzer Configure first FortiAnalyzer device.
fortiguard Configure log for FortiGuard.
gui-display Configure log GUI display settings.
memory Configure memory log.
setting Configure general log settings.
syslogd Configure first syslog device.
threat-weight Configure threat weight settings.
 
Global options:
 
FIREWALL (global) # config log
fortianalyzer Configure first FortiAnalyzer device.
fortianalyzer2 Configure second FortiAnalyzer device.
fortianalyzer3 Configure third FortiAnalyzer device.
fortiguard Configure log for FortiGuard.
memory Configure memory log.
syslogd Configure first syslog device.
syslogd2 Configure second syslog device.
syslogd3 Configure third syslog device.
webtrends Configure Web trends.
 
Am I missing something? 
 
Any help much appreciated, 

Cheers

Jon
#1
Jeff_FTNT
Gold Member
  • Total Posts : 228
  • Scores: 21
  • Reward points: 0
  • Joined: 2005/06/14 16:27:00
  • Status: offline
Re: Logging to multiple Syslog servers VDOM 2016/08/29 08:23:12 (permalink)
5 (1)
Hello,
Each VDOM it can set up override syslog like CLI:config  log  syslogd  override-setting , it only can set up one.
Only this specific VDOM log sends to override syslogs.
On global, it can set up 3 syslog  server , all VDOM log will send to 3 different syslog server through Management VDOM, thanks.
#2
emnoc
Expert Member
  • Total Posts : 5208
  • Scores: 339
  • Reward points: 0
  • Joined: 2008/03/20 13:30:33
  • Location: AUSTIN TX AREA
  • Status: offline
Re: Logging to multiple Syslog servers VDOM 2016/09/07 13:25:19 (permalink) ☄ Helpfulby CrazyCatMan 2019/02/24 21:41:35
5 (1)
It's doable and little hidden
 
You have to enable it ; and then magically you can set the server ;)
 
 
config log syslogd override-setting
    set override enable  <----HERE
    set status enable  <----HERE
    set server "10.1.1.31"  <-----HERE
end

PCNSE,  NSE , Forcepoint ,  StrongSwan Specialist
#3
CrazyCatMan
New Member
  • Total Posts : 4
  • Scores: 0
  • Reward points: 0
  • Status: offline
Re: Logging to multiple Syslog servers VDOM 2019/02/24 21:41:49 (permalink)
0
Thanks for this. Was what I needed.
#4
Medson1989
New Member
  • Total Posts : 1
  • Scores: 0
  • Reward points: 0
  • Joined: 2019/07/14 02:57:06
  • Status: offline
Re: Logging to multiple Syslog servers VDOM 2019/07/14 03:01:02 (permalink)
0
Hello ,
 
In case of SYSLOG and other services that using specific ports.
Do we need to open the port and configure policy ?
In which cases we need policy for them ?
 
thanks
#5
DW_FTNT
New Member
  • Total Posts : 7
  • Scores: 2
  • Reward points: 0
  • Joined: 2019/08/12 07:38:28
  • Status: offline
Re: Logging to multiple Syslog servers VDOM 2019/08/12 09:10:13 (permalink)
#6
Jump to:
© 2019 APG vNext Commercial Version 5.5