Centralized log management is a critical requirement for security operations centers (SOCs) and regulatory compliance frameworks. While FortiGate firewalls provide robust local logging and integration with FortiAnalyzer, transmitting log data to a third-party Security Information and Event Management (SIEM) platform is a standard architectural pattern. Implementing a proper FortiGate syslog configuration ensures that security analysts receive actionable, real-time threat intelligence and traffic events across the enterprise network.
This technical guide demonstrates how to configure, test, and troubleshoot Syslog event forwarding from FortiOS to a central SIEM collector using both the Graphical User Interface (GUI) and Command Line Interface (CLI).
Real-Life Scenario
An enterprise organization requires all network edge security events forwarded to a central SIEM collector (such as Splunk, Microsoft Sentinel, or IBM QRadar) for real-time analysis, automated correlation, and multi-year retention. The SOC team mandates that traffic logs, threat detections, system events, and administrative activities generated by core FortiGate firewalls be securely delivered using standard Syslog protocols over UDP or TCP with zero impact on firewall processing performance.
Lab Topology
The following ASCII network diagram illustrates the operational layout for this deployment. Traffic passing through the FortiGate triggers log entries that are formatted and forwarded across the internal management network to the designated Syslog/SIEM server.
+---------------------+ +------------------------+
| Internet / WAN | | Internal LAN Host |
| 198.51.100.0/24 | | 10.0.20.100/24 |
+----------+----------+ +-----------+------------+
| |
| port1 (WAN) | port2 (LAN)
+-----------------+------------------+
|
+---------+----------+
| FortiGate 100F |
| FortiOS 7.2.x |
+---------+----------+
|
| port3 (Mgmt/SIEM Zone)
| 10.0.10.1/24
|
+-------------+--------------+
| SIEM / Syslog Server |
| 10.0.10.50/24 |
| Listening: 514 |
+----------------------------+
Example Addressing and Objects
The following LAB values represent the network configuration throughout this tutorial. Adapt these values to match your specific production environment.
| Device / Interface | Context / Role | IP Address / Subnet | Lab Notes |
|---|---|---|---|
FortiGate port1 |
WAN Interface | 198.51.100.254/24 |
Egress to public untrusted networks (RFC 5737). |
FortiGate port2 |
LAN Interface | 10.0.20.1/24 |
Gateway for internal user segments. |
FortiGate port3 |
SIEM / Mgmt Interface | 10.0.10.1/24 |
Bind interface for outbound Syslog traffic. |
SIEM Collector |
Syslog Receiver | 10.0.10.50/24 |
Listens on UDP/514 for raw or CEF formatted logs. |
Prerequisites
- A deployed FortiGate unit running FortiOS 6.4, 7.0, 7.2, or 7.4.
- Administrative access to the FortiGate via HTTPS GUI and SSH CLI.
- Network reachability between the FortiGate interface and the SIEM collector address.
- Firewall rules enabled on intermediate network devices permitting UDP port 514 (or TCP port 514 / TLS port 6514 if using reliable/encrypted transmission).
Step-by-Step GUI Configuration
Note: GUI paths and parameter layout can vary slightly depending on the active FortiOS release version, VDOM setup, and feature visibility settings.
- Log in to the FortiGate GUI using administrative credentials.
- Navigate to Log & Report > Log Settings.
- In the main configuration pane, scroll down to the Remote Logging Options section.
- Enable the toggle switch for Send Logs to Syslog.
- Enter the lab SIEM server IP address:
10.0.10.50into the IP Address/FQDN field. - Specify the target port (Default:
514). - Select the desired Syslog Format (e.g.,
Defaultfor native log structure, orCEFif required by your SIEM solution). - Set the Facility value (e.g.,
local7) to allow destination receivers to classify incoming traffic correctly. - Click Apply at the bottom of the page to save changes.
Step-by-Step FortiGate Syslog Configuration via CLI
Configuring remote logging via the CLI offers enhanced granular control, such as explicit source-IP binding, mode selection, and custom transmission rates. FortiOS supports multiple Syslog destinations (e.g., syslogd, syslogd2, syslogd3, syslogd4).
1. Basic Remote Syslog Server Setup
Execute the following commands to configure the primary Syslog daemon daemon settings on the FortiGate:
config log syslogd setting
set status enable
set server "10.0.10.50"
set mode udp
set port 514
set facility local7
set format default
set source-ip "10.0.10.1"
set max-log-rate 0
set priority default
end
Understanding CLI Configuration Parameters
set status enable: Activates the primary Syslog logging engine.set server "10.0.10.50": Defines the destination IP address of the SIEM collector.set mode udp: Specifies the transport layer protocol. Options includeudp,legacy-ssl, andreliable(TCP).set port 514: Designates the destination port listening on the remote receiver.set facility local7: Sets the standard Syslog facility code for log filtering on syslog daemons (e.g., rsyslog, syslog-ng).set format default: Dictates log output syntax. Options typically includedefault(key-value plain text) orcef(Common Event Format).set source-ip "10.0.10.1": Binds log packets to a specific local interface address to ensure deterministic routing and SIEM sender identification.set max-log-rate 0: Defines the log rate limit in logs per second. Setting this value to0disables rate-limiting (unlimited transmission).
2. Enabling Log Generation within Firewall Policies
Configuring remote Syslog settings initiates the daemon service, but FortiGate does not forward traffic event logs unless the corresponding firewall policies are explicitly set to record session events.
config firewall policy
edit 1
set name "LAN_to_WAN_Access"
set srcintf "port2"
set dstintf "port1"
set action accept
set srcaddr "all"
set dstaddr "all"
set schedule "always"
set service "ALL"
set nat enable
set logtraffic all
next
end
Setting set logtraffic all ensures that both session start and session close/termination actions trigger log output. For high-volume environments, set logtraffic utm can be used to limit logs exclusively to Security Profile threat detections (such as AV, IPS, Web Filter, and Application Control).
How the Traffic Flows
Understanding the internal logging lifecycle assists engineers in isolating delivery failures between packet creation and transport layers.
- Event Generation: A network connection flows through the FortiGate, matching a configured firewall policy, or a system event occurs (such as an admin login or HA state change).
- Log Evaluation: The FortiOS kernel inspects policy flags (e.g.,
logtraffic all). If logging is enabled, an internal event log entry is written to memory buffers. - Formatting Engine: The local logging daemon (
logd) formats the event details into specified key-value strings or Common Event Format (CEF) key pairs. - Socket Creation & Binding: The Syslog output handler encapsulates the payload into a standard Syslog message body. It attaches the configured
source-ipaddress as the layer-3 sender header. - Routing Lookup: FortiOS performs an internal FIB (Forwarding Information Base) routing table lookup for the destination SIEM address (e.g.,
10.0.10.50). - Egress Transmission: Packets exit the physical interface (e.g.,
port3) addressed to UDP/TCP port 514 on the SIEM server.
Verification
Once configured, verify operational delivery using system-level verification commands.
1. Generate Test Syslog Events
FortiOS provides an explicit execution command to push test messages directly to configured remote Syslog daemons:
execute log syslog test
This command injects dummy log events into the system logging pipeline, pushing test records to all actively configured Syslog destinations regardless of current live network traffic levels.
2. Verify Active Logging Status via CLI
Inspect the local state of the Syslog logging engine using the following display commands:
execute log display
To inspect active status flags for remote Syslog output explicitly, review log status output via CLI:
diagnose log device
Verify that the remote Syslog entry displays status: free/ready and records an increasing log count under sending stats.
Troubleshooting
When SIEM platform collectors do not receive FortiGate log records, systematically apply the diagnostic workflow below to identify and resolve the operational issue.
Step 1: Check Routing and Egress Interface Reachability
Execute a ping test sourced explicitly from the bound Syslog source IP address to verify basic network connectivity:
execute ping-options source 10.0.10.1 execute ping 10.0.10.50
If ping attempts fail, evaluate local static routes, interface subnet masks, and upstream routing devices.
Step 2: Perform Real-Time Packet Captures
Run a packet trace on the FortiGate CLI to confirm that outbound network packets are physically departing the interface when events occur:
diagnose sniffer packet any 'host 10.0.10.50 and port 514' 4 10 a
Expected Output: Output showing outbound UDP or TCP frames originating from the FortiGate source IP to the SIEM receiver IP.
Step 3: Debug Log Daemon Activity
If network reachability is confirmed but packets are not departing the firewall, run the application-level debug process for the logging daemon.
Enable the interactive logging daemon debug output:
diagnose debug application logd -1 diagnose debug enable
While debug trace logging is active, trigger a test log using execute log syslog test in a secondary CLI session. Look for socket allocation errors, memory buffer limits, or configuration mismatch messages in the diagnostic terminal window.
Mandatory Cleanup Step: Once diagnostic testing is finished, execute the following commands to disable debug trace functions and reset system diagnostics:
diagnose debug disable diagnose debug reset
Common Mistakes
- Unbound Source IP Address: Failing to configure
set source-ipon multi-interface or VDOM deployments. This causes FortiOS to choose egress interface addresses arbitrarily, leading to dropped packets at upstream firewalls or SIEM ingestion filters. - Omitted Policy-Level Logging: Configuring global Syslog settings without setting
set logtraffic allorset logtraffic utmon active firewall policies. - UDP Packet Loss Under High Load: Transporting enterprise-scale log streams over unacknowledged UDP connections across congested links, resulting in silent packet drops. Consider using
reliablemode (TCP) or TLS for critical destinations. - Ingestion Format Mismatch: Selecting standard plain-text formatting when the SIEM collector expects structured Common Event Format (CEF) fields, resulting in unparsed or unindexed raw string entries.
- VDOM Context Scope Issues: Applying Syslog commands within a non-management Virtual Domain (VDOM) when global system routing requires management interface execution.
Production Considerations
1. High Availability (HA) Deployments
In an Active-Passive FortiGate HA cluster, the primary unit processes traffic and generates all runtime logs. If a failover occurs, the secondary unit assumes master status and begins sourcing Syslog events. Ensure that your SIEM parsing rules account for both HA member cluster node names or configure an identical source-ip across both nodes if reachable via shared management infrastructure.
2. VDOM Architecture Considerations
If Virtual Domains (VDOMs) are enabled on the FortiGate, Syslog options are managed at the global or per-VDOM scope depending on configuration options:
config global
config log syslogd setting
set status enable
set server "10.0.10.50"
end
end
Individual VDOMs can inherit global logging profiles or override daemon settings depending on specific organizational compliance demands.
3. Transport Reliability vs CPU Impact
While standard UDP transmission imposes minimal performance overhead on FortiGate network processors, reliable mode (TCP) introduces TCP state management overhead. If using reliable encrypted transport (TLS), ensure firewall hardware supports SSL offloading to prevent resource exhaustion during heavy security event bursts.
Related FortiGate Guides
- FortiGate session troubleshooting
- FortiGate packet sniffer and debug flow
- FortiGate security profiles
- FortiGate SSL deep inspection
Summary
A properly executed FortiGate syslog configuration is essential for real-time threat intelligence and SOC visibility. By ensuring accurate firewall policy settings, binding explicit source IPs, selecting the correct transport mode, and performing step-by-step verification, network security engineers can establish dependable, performant event streaming to enterprise SIEM platforms.