FortiClient
FortiClient proactively defends against advanced attacks. Its tight integration with the Security Fabric enables policy-based automation to contain threats and control outbreaks. FortiClient is compatible with Fabric-Ready partners to further strengthen enterprises’ security posture.
Jonathan_Body_FTNT
Article Id 197334

Description

FortiClient Premium Edition allows users to enable logging to a Fortinet FortiAnalyzer device or to a third-party Syslog device, this article shows how to enable this feature using the FortiClient Console.


Scope

All FortiClient Premium Users


Solution

With a FortiClient Premium Edition License successfully activated, a FortiClient user can connect via the FortiClient Console to activate remote logging to either a Fortinet FortiAnalyzer device or Syslog Server. 

Simply connect to the FortiClient Console and complete the following steps from the "General>Log Settings"

1. Determine "Maximum Log Size"

jbody_FD31748_Knova179.jpg

2. In Event Log Settings set the "Log Level" and "What to log" parameters, in the below example the "Log Level" is set to "Warning" and "What to log" is set to "All events"

jbody_FD31748_FD31750_Knova182.jpg

3. Specify in the "Remote Logging" section the Server's IP address to log to, the logging facilities to be used, whether the logging device is a Fortinet FortiAnalyzer device or Syslog Server, and in the latter case the Syslog log level to be used. The Event Log Settings "Log Level" will determine the log level used with a Fortinet FortiAnalyzer device. In the below example a Syslog server is used with the default values of "local 7" for "Facilities" and the Syslog log level of "Warning"

jbody_FD31748_FD31750_Knova183.jpg

4. To save these settings select "Apply" and the FortiClient is ready to log to the above specified Syslog server:-

jbody_FD31748_FD31750_Knova184.jpg





Contributors