Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
HighlyVolatile
New Contributor

FortiOS 6.0.1 - Not sending traffic logs to FortiAnalyzer

Hi all,

 

I am currently having an issue with the traffic logs on a Fortigate 1500D, and I am out of ideas as to what the root cause is. The Fortigate is currently running 6.0.1 with multiple VDOMs, and it has been configured to send logging messages to a FortiAnalyzer unit running 6.2.2.

 

It was working fine until around 2 months ago, when it suddenly stopped sending traffic logs to FortiAnalyzer. However, it is still sending the event logs.

 

The policies are configured to 'log all', and I can see matching traffic if I open the traffic logs and set the location to disk/memory. However, if I view the logs sent to FortiAnalyzer, it will only show traffic that has hit the implicit deny rule.

 

On the FortiAnalyzer, I can see the event log file under 'Log Browse', however there is nothing for traffic logs, so I assume the Fortigate is at fault.

 

I have read the Fortinet support documentation and I believe I have covered all of the obvious areas such as checking the connection from the CLI and setting the severity level to information.

 

The FortiAnalyzer unit is also collecting logs for three other firewalls, and I have compared the working units against this one, and I cannot see any differences.

 

Does anyone have any advice on how to rectify this problem?

 

Thank you for your help.

0 REPLIES 0
Labels
Top Kudoed Authors