如何将Fortigate(VM)日志通过IP传输至ELK?新手求助
How to Forward Fortigate Logs to ELK via IP Address
Hey there! I get that setting up log forwarding between Fortigate and ELK can feel tricky when you're just starting out—let's walk through this step by step so you can get those logs flowing.
Step 1: Configure Fortigate to Send Logs to ELK's IP
First, we need to tell your Fortigate to send its logs directly to your ELK server's IP address:
- Log into your Fortigate web admin interface.
- Navigate to Log & Report > Log Settings (some older versions might have this under System > Log Settings).
- Look for the Remote Logging section, then click Add Remote Server.
- Fill in your ELK server's IP Address.
- Choose a protocol: UDP is the default and most common for syslog, but TCP is more reliable if you need to avoid log loss.
- Set the port to
514(this is the standard syslog port; we'll configure Logstash to listen on this next). - Select which log types you want to send (e.g., Traffic, Event, Security—pick what matters to you).
- Save the configuration and click Apply to make the changes take effect.
Step 2: Set Up Logstash to Receive Fortigate Syslogs
ELK uses Logstash (or sometimes Filebeat) to ingest external logs. Here's how to configure Logstash to listen for Fortigate's syslog traffic:
- Create a new Logstash config file in the config directory (usually
/etc/logstash/conf.d/). Name it something likefortigate-syslog.conf. - Paste this configuration into the file (adjust values to match your setup):
# Input: Listen for syslog traffic on port 514 input { syslog { port => 514 type => "fortigate" codec => "plain" } } # Filter: Parse Fortigate's syslog format into structured data filter { if [type] == "fortigate" { grok { match => { "message" => "%{SYSLOGTIMESTAMP:timestamp} %{SYSLOGHOST:hostname} %{DATA:process}(?:\[%{POSINT:pid}\])?: %{GREEDYDATA:msg}" } } date { match => [ "timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss" ] timezone => "Asia/Shanghai" # Replace with your local timezone (e.g., UTC, Europe/London) } } } # Output: Send parsed logs to Elasticsearch output { elasticsearch { hosts => ["localhost:9200"] # Replace with your Elasticsearch IP:port if it's not local index => "fortigate-%{+YYYY.MM.dd}" } stdout { codec => rubydebug } # Optional: Prints logs to console for debugging }
- Save the file, then restart Logstash to apply the changes:
sudo systemctl restart logstash
Step 3: Verify the Setup & Troubleshoot
Now let's make sure everything works as expected:
- Trigger some logs on your Fortigate (e.g., browse a website through the firewall, or make a small configuration change).
- Check if Elasticsearch is receiving the logs: Open Kibana, create an index pattern for
fortigate-*, and you should see your Fortigate logs show up. - If logs aren't appearing:
- Check network connectivity: Ping your ELK server from Fortigate, and vice versa, to confirm they can reach each other.
- Verify firewall rules: Ensure Fortigate is allowed to send traffic to ELK's port 514, and your ELK server's firewall allows incoming traffic on that port.
- Check Logstash logs: Run
sudo journalctl -u logstashto look for any configuration errors or connection issues. - Test with tcpdump: On your ELK server, run
sudo tcpdump -i any port 514—you should see packets coming from your Fortigate's IP if the connection is working.
内容的提问来源于stack exchange,提问作者Hellmaster
相关产品推荐
相关产品推荐

