Centralized log management is a critical requirement for security operations centers (SOCs) and regulatory compliance frameworks. While FortiGate firewalls provide robust local logging and integration with FortiAnalyzer, transmitting log data to a third-party Security Information and Event Management (SIEM) platform is a standard architectural pattern. Implementing a proper FortiGate syslog configuration ensures that security analysts receive actionable, real-time threat intelligence and traffic events across the enterprise network.

This technical guide demonstrates how to configure, test, and troubleshoot Syslog event forwarding from FortiOS to a central SIEM collector using both the Graphical User Interface (GUI) and Command Line Interface (CLI).

Real-Life Scenario

An enterprise organization requires all network edge security events forwarded to a central SIEM collector (such as Splunk, Microsoft Sentinel, or IBM QRadar) for real-time analysis, automated correlation, and multi-year retention. The SOC team mandates that traffic logs, threat detections, system events, and administrative activities generated by core FortiGate firewalls be securely delivered using standard Syslog protocols over UDP or TCP with zero impact on firewall processing performance.

Lab Topology

The following ASCII network diagram illustrates the operational layout for this deployment. Traffic passing through the FortiGate triggers log entries that are formatted and forwarded across the internal management network to the designated Syslog/SIEM server.

+---------------------+             +------------------------+
|   Internet / WAN    |             |   Internal LAN Host    |
|   198.51.100.0/24   |             |     10.0.20.100/24     |
+----------+----------+             +-----------+------------+
           |                                    |
           | port1 (WAN)                        | port2 (LAN)
           +-----------------+------------------+
                             |
                   +---------+----------+
                   |  FortiGate 100F    |
                   |  FortiOS 7.2.x     |
                   +---------+----------+
                             |
                             | port3 (Mgmt/SIEM Zone)
                             | 10.0.10.1/24
                             |
               +-------------+--------------+
               |   SIEM / Syslog Server     |
               |      10.0.10.50/24         |
               |     Listening: 514         |
               +----------------------------+

Example Addressing and Objects

The following LAB values represent the network configuration throughout this tutorial. Adapt these values to match your specific production environment.

Device / Interface Context / Role IP Address / Subnet Lab Notes
FortiGate port1 WAN Interface 198.51.100.254/24 Egress to public untrusted networks (RFC 5737).
FortiGate port2 LAN Interface 10.0.20.1/24 Gateway for internal user segments.
FortiGate port3 SIEM / Mgmt Interface 10.0.10.1/24 Bind interface for outbound Syslog traffic.
SIEM Collector Syslog Receiver 10.0.10.50/24 Listens on UDP/514 for raw or CEF formatted logs.

Prerequisites

  • A deployed FortiGate unit running FortiOS 6.4, 7.0, 7.2, or 7.4.
  • Administrative access to the FortiGate via HTTPS GUI and SSH CLI.
  • Network reachability between the FortiGate interface and the SIEM collector address.
  • Firewall rules enabled on intermediate network devices permitting UDP port 514 (or TCP port 514 / TLS port 6514 if using reliable/encrypted transmission).

Step-by-Step GUI Configuration

Note: GUI paths and parameter layout can vary slightly depending on the active FortiOS release version, VDOM setup, and feature visibility settings.

  1. Log in to the FortiGate GUI using administrative credentials.
  2. Navigate to Log & Report > Log Settings.
  3. In the main configuration pane, scroll down to the Remote Logging Options section.
  4. Enable the toggle switch for Send Logs to Syslog.
  5. Enter the lab SIEM server IP address: 10.0.10.50 into the IP Address/FQDN field.
  6. Specify the target port (Default: 514).
  7. Select the desired Syslog Format (e.g., Default for native log structure, or CEF if required by your SIEM solution).
  8. Set the Facility value (e.g., local7) to allow destination receivers to classify incoming traffic correctly.
  9. Click Apply at the bottom of the page to save changes.

Step-by-Step FortiGate Syslog Configuration via CLI

Configuring remote logging via the CLI offers enhanced granular control, such as explicit source-IP binding, mode selection, and custom transmission rates. FortiOS supports multiple Syslog destinations (e.g., syslogd, syslogd2, syslogd3, syslogd4).

1. Basic Remote Syslog Server Setup

Execute the following commands to configure the primary Syslog daemon daemon settings on the FortiGate:

config log syslogd setting
    set status enable
    set server "10.0.10.50"
    set mode udp
    set port 514
    set facility local7
    set format default
    set source-ip "10.0.10.1"
    set max-log-rate 0
    set priority default
end

Understanding CLI Configuration Parameters

  • set status enable: Activates the primary Syslog logging engine.
  • set server "10.0.10.50": Defines the destination IP address of the SIEM collector.
  • set mode udp: Specifies the transport layer protocol. Options include udp, legacy-ssl, and reliable (TCP).
  • set port 514: Designates the destination port listening on the remote receiver.
  • set facility local7: Sets the standard Syslog facility code for log filtering on syslog daemons (e.g., rsyslog, syslog-ng).
  • set format default: Dictates log output syntax. Options typically include default (key-value plain text) or cef (Common Event Format).
  • set source-ip "10.0.10.1": Binds log packets to a specific local interface address to ensure deterministic routing and SIEM sender identification.
  • set max-log-rate 0: Defines the log rate limit in logs per second. Setting this value to 0 disables rate-limiting (unlimited transmission).

2. Enabling Log Generation within Firewall Policies

Configuring remote Syslog settings initiates the daemon service, but FortiGate does not forward traffic event logs unless the corresponding firewall policies are explicitly set to record session events.

config firewall policy
    edit 1
        set name "LAN_to_WAN_Access"
        set srcintf "port2"
        set dstintf "port1"
        set action accept
        set srcaddr "all"
        set dstaddr "all"
        set schedule "always"
        set service "ALL"
        set nat enable
        set logtraffic all
    next
end

Setting set logtraffic all ensures that both session start and session close/termination actions trigger log output. For high-volume environments, set logtraffic utm can be used to limit logs exclusively to Security Profile threat detections (such as AV, IPS, Web Filter, and Application Control).

How the Traffic Flows

Understanding the internal logging lifecycle assists engineers in isolating delivery failures between packet creation and transport layers.

  1. Event Generation: A network connection flows through the FortiGate, matching a configured firewall policy, or a system event occurs (such as an admin login or HA state change).
  2. Log Evaluation: The FortiOS kernel inspects policy flags (e.g., logtraffic all). If logging is enabled, an internal event log entry is written to memory buffers.
  3. Formatting Engine: The local logging daemon (logd) formats the event details into specified key-value strings or Common Event Format (CEF) key pairs.
  4. Socket Creation & Binding: The Syslog output handler encapsulates the payload into a standard Syslog message body. It attaches the configured source-ip address as the layer-3 sender header.
  5. Routing Lookup: FortiOS performs an internal FIB (Forwarding Information Base) routing table lookup for the destination SIEM address (e.g., 10.0.10.50).
  6. Egress Transmission: Packets exit the physical interface (e.g., port3) addressed to UDP/TCP port 514 on the SIEM server.

Verification

Once configured, verify operational delivery using system-level verification commands.

1. Generate Test Syslog Events

FortiOS provides an explicit execution command to push test messages directly to configured remote Syslog daemons:

execute log syslog test

This command injects dummy log events into the system logging pipeline, pushing test records to all actively configured Syslog destinations regardless of current live network traffic levels.

2. Verify Active Logging Status via CLI

Inspect the local state of the Syslog logging engine using the following display commands:

execute log display

To inspect active status flags for remote Syslog output explicitly, review log status output via CLI:

diagnose log device

Verify that the remote Syslog entry displays status: free/ready and records an increasing log count under sending stats.

Troubleshooting

When SIEM platform collectors do not receive FortiGate log records, systematically apply the diagnostic workflow below to identify and resolve the operational issue.

Step 1: Check Routing and Egress Interface Reachability

Execute a ping test sourced explicitly from the bound Syslog source IP address to verify basic network connectivity:

execute ping-options source 10.0.10.1
execute ping 10.0.10.50

If ping attempts fail, evaluate local static routes, interface subnet masks, and upstream routing devices.

Step 2: Perform Real-Time Packet Captures

Run a packet trace on the FortiGate CLI to confirm that outbound network packets are physically departing the interface when events occur:

diagnose sniffer packet any 'host 10.0.10.50 and port 514' 4 10 a

Expected Output: Output showing outbound UDP or TCP frames originating from the FortiGate source IP to the SIEM receiver IP.

Step 3: Debug Log Daemon Activity

If network reachability is confirmed but packets are not departing the firewall, run the application-level debug process for the logging daemon.

CAUTION: Interactive debug commands increase CPU usage and generate verbose console output. Always stop debugging output immediately upon completion of testing using the cleanup commands provided below.

Enable the interactive logging daemon debug output:

diagnose debug application logd -1
diagnose debug enable

While debug trace logging is active, trigger a test log using execute log syslog test in a secondary CLI session. Look for socket allocation errors, memory buffer limits, or configuration mismatch messages in the diagnostic terminal window.

Mandatory Cleanup Step: Once diagnostic testing is finished, execute the following commands to disable debug trace functions and reset system diagnostics:

diagnose debug disable
diagnose debug reset

Common Mistakes

  • Unbound Source IP Address: Failing to configure set source-ip on multi-interface or VDOM deployments. This causes FortiOS to choose egress interface addresses arbitrarily, leading to dropped packets at upstream firewalls or SIEM ingestion filters.
  • Omitted Policy-Level Logging: Configuring global Syslog settings without setting set logtraffic all or set logtraffic utm on active firewall policies.
  • UDP Packet Loss Under High Load: Transporting enterprise-scale log streams over unacknowledged UDP connections across congested links, resulting in silent packet drops. Consider using reliable mode (TCP) or TLS for critical destinations.
  • Ingestion Format Mismatch: Selecting standard plain-text formatting when the SIEM collector expects structured Common Event Format (CEF) fields, resulting in unparsed or unindexed raw string entries.
  • VDOM Context Scope Issues: Applying Syslog commands within a non-management Virtual Domain (VDOM) when global system routing requires management interface execution.

Production Considerations

1. High Availability (HA) Deployments

In an Active-Passive FortiGate HA cluster, the primary unit processes traffic and generates all runtime logs. If a failover occurs, the secondary unit assumes master status and begins sourcing Syslog events. Ensure that your SIEM parsing rules account for both HA member cluster node names or configure an identical source-ip across both nodes if reachable via shared management infrastructure.

2. VDOM Architecture Considerations

If Virtual Domains (VDOMs) are enabled on the FortiGate, Syslog options are managed at the global or per-VDOM scope depending on configuration options:

config global
    config log syslogd setting
        set status enable
        set server "10.0.10.50"
    end
end

Individual VDOMs can inherit global logging profiles or override daemon settings depending on specific organizational compliance demands.

3. Transport Reliability vs CPU Impact

While standard UDP transmission imposes minimal performance overhead on FortiGate network processors, reliable mode (TCP) introduces TCP state management overhead. If using reliable encrypted transport (TLS), ensure firewall hardware supports SSL offloading to prevent resource exhaustion during heavy security event bursts.

Related FortiGate Guides

Summary

A properly executed FortiGate syslog configuration is essential for real-time threat intelligence and SOC visibility. By ensuring accurate firewall policy settings, binding explicit source IPs, selecting the correct transport mode, and performing step-by-step verification, network security engineers can establish dependable, performant event streaming to enterprise SIEM platforms.