FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
KenYap
Staff
Staff
Article Id 297594
Description This article describes how to check which FortiGate VDOM is using which interface to send logs to FortiAnalyzer.
Scope FortiAnalyzer.
Solution

Below are the scenarios:

  1. FortiGate VDOM does not enable the FortiAnalyzer Override Setting.
  2. FortiGate VDOM enables the FortiAnalyzer Override Setting.

 

Below are the ports assignation at different VDOMS.

In this example, 'root' VDOM and 'vdom_A' VDOM.

  • 'root' VDOM is assigned at port1.
  • 'vdom_A' VDOM is assigned at port2.

 

LogOverrideSettings_001.PNG

 

The static route is configured at 'root' VDOM and 'vdom_A' VDOM, so both VDOMs will know which interface to go out and reach FortiAnalyzer.

 

LogOverrideSettings_002.PNG

 

Scenario 1:

FortiAnalyzer settings are configured in the Global setting, but FortiGate 'vdom_A' VDOM does not enable the FortiAnalyzer Override Setting.

 

LogOverrideSettings_003.PNG

 

Use the steps below to verify which FortiGate 'vdom_A' VDOM is using which interface to go out and reach FortiAnalyzer.

 

LogOverrideSettings_004.PNG

 

LogOverrideSettings_005.PNG

 

 

Scenario 2:

The FortiAnalyzer settings are configured in the Global setting, and FortiGate 'vdom_A' VDOM enables the FortiAnalyzer Override Setting. 

 

LogOverrideSettings_006.PNG

  

Use the steps below to verify which FortiGate 'vdom_A' VDOM is using which interface to go out and reach FortiAnalyzer.

 

LogOverrideSettings_007.PNG

 

LogOverrideSettings_008.PNG

 

Related Article:

Troubleshooting Tip: FortiGate to FortiAnalyzer connectivity