FortiGate Firewall Audit

Enabling Syslog Events Forwarding in FortiGate

Access the firewall console and execute the following:

config log syslogd setting
set status enable
set server <Monitoring Node IP>
set reliable disable
set port 514
set csv disable
set facility local1
set source-ip <FortiGate IP>

Configuring through the FortiGate Firewall Network Interface

The FortiGate Firewall can also be configured using the FortiGate Firewall Network Interface as shown in the image below.

IMPORTANT: The IP Address/FQSN setting should be that of the device on which Event Manager is installed: