# Fortigate / fortinet Logs not collected

**URL:** https://community.graylog.org/t/fortigate-fortinet-logs-not-collected/17257
**Category:** Graylog Central (peer support)
**Created:** [September 22, 2020, 11:51am UTC](https://community.graylog.org/t/fortigate-fortinet-logs-not-collected/17257 "2020-09-22T11:51:20Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![al-ka](https://avatars.discourse-cdn.com/v4/letter/a/e47c2d/32.png) [@al-ka](https://community.graylog.org/u/al-ka)
#### Post date: [September 22, 2020, 11:51am UTC](https://community.graylog.org/t/fortigate-fortinet-logs-not-collected/17257/1 "2020-09-22T11:51:20Z")

</div>

Hello all,

I have issue with fortigate VPN logs on graylog. Even though I can see that fortigate sends the sylogs to graylog and I can see them with tcpdump but graylog not receiving them.

I tried different port numbers like 1514, 15514 and different inputs like syslog udp, plaintext udp., cef udp but still nothing received. I have other inputs from other devices and no issues. Also same fortigate device sends logs to rsyslog without any issue.

I checked date and time settings on both fortigate and graylog, they are identical.

Am I missing something? Please advise.

Thank you very much in advance.

Al

---

<div class="post-metadata">

### Author: ![shoothub](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/shoothub/32/6412_2.png) [@shoothub](https://community.graylog.org/u/shoothub)
#### Post date: [September 22, 2020, 1:18pm UTC](https://community.graylog.org/t/fortigate-fortinet-logs-not-collected/17257/2 "2020-09-22T13:18:42Z")

</div>

1. Check if you use correct fortigate configuration for syslog. Don’t use reliable delivery  
[https://kb.fortinet.com/kb/documentLink.do?externalID=FD44614](https://kb.fortinet.com/kb/documentLink.do?externalID=FD44614)
2. Try to use Raw UDP input
3. Check if you can’t see fortigate logs in future. Graylog by default only show logs from now to past. If logs are stored with furure timestamps it can’t show it. Try to use absolute time in search and select timeframe from today to at least one day in future.

---

<div class="post-metadata">

### Author: ![al-ka](https://avatars.discourse-cdn.com/v4/letter/a/e47c2d/32.png) [@al-ka](https://community.graylog.org/u/al-ka)
#### Post date: [September 23, 2020, 7:35am UTC](https://community.graylog.org/t/fortigate-fortinet-logs-not-collected/17257/3 "2020-09-23T07:35:26Z")

</div>

Hello Shoothub,

Thank your for your input but I already checked the forums and tried those but no result.  
Logs are coming to graylog server, I can see them with TCPDUMP but graylog doesn’t even receive them. When I check the input I see 0 msg/s.

Regards,  
Al

---

<div class="post-metadata">

### Author: ![al-ka](https://avatars.discourse-cdn.com/v4/letter/a/e47c2d/32.png) [@al-ka](https://community.graylog.org/u/al-ka)
#### Post date: [September 24, 2020, 9:51am UTC](https://community.graylog.org/t/fortigate-fortinet-logs-not-collected/17257/4 "2020-09-24T09:51:33Z")

</div>

It was related to network settings. It is solved after I solved the routing.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)
#### Post date: [October 8, 2020, 9:51am UTC](https://community.graylog.org/t/fortigate-fortinet-logs-not-collected/17257/5 "2020-10-08T09:51:37Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
