Back to Blog
Hardware & Software

How to Configure FortiGate Logging: Syslog, Disk, and FortiAnalyzer (2026)

How to Configure FortiGate Logging: Syslog, Disk, and FortiAnalyzer (2026)
How to set up FortiGate logging: traffic/event/security logs, disk vs syslog, FortiAnalyzer, retention, and practical settings for 5651/ISO 27001 evidence.
Published
July 29, 2026
Updated
July 29, 2026
Reading Time
14 min read
Author
LeonX Expert Team

FortiGate logging sends traffic, event, and security records to disk, syslog/SIEM, or FortiAnalyzer so you get visibility and audit evidence. Short answer: enable logging, choose which log types go where, turn on log allowed/denied on policies, define a central destination, and size retention for compliance. Logs kept only on the appliance disappear when the disk fills—production needs a central archive.

This guide is written for:

  • Network and security teams operating FortiGate
  • SOC/ops teams deploying SIEM or FortiAnalyzer
  • IT managers producing evidence for Law No. 5651 and ISO 27001
  • Decision makers standardizing edge visibility

Quick Summary

  • FortiGate has three main families: Traffic, Event, and Security logs.
  • If logging is off on a policy, allowed traffic can be invisible—enable log on critical allow/deny rules.
  • On-box disk is for short-term troubleshooting; use syslog/SIEM or FortiAnalyzer for long retention.
  • Wrong NTP breaks timestamp trust in audits.
  • For 5651, firewall logs alone may be insufficient—plan DHCP/NAT/identity layers too.
  • ISO 27001 evidence needs logging + monitoring + defined retention together.

Table of Contents

How to configure FortiGate logging

Image: Wikimedia Commons - Img atp800 p 01 (example enterprise security appliance form factor).

What Is FortiGate Logging?

FortiGate writes session and security events to configurable destinations. For product context, see What Is a FortiGate Firewall?; for session/policy behavior, see How Does a Fortinet Firewall Work?.

Short definition:

FortiGate logging is the process of sending traffic/event/security records to disk, memory, syslog/SIEM, or FortiAnalyzer to support operations, forensics, and compliance evidence.

Without logs, even a correct policy cannot answer “who went where, when?” For policy design, see Policy Configuration.

Log Types

TypeWhat it recordsTypical use
TrafficAllow/deny sessions, bytes, policy IDAccess and capacity analysis
EventSystem, HA, admin, VPN eventsOps and change trail
SecurityIPS, AV, web filter, app controlThreat and UTM review

Security logs depend on FortiGuard profiles; without licenses, expected records will not appear: Fortinet License Types.

Step-by-Step Configuration

  1. Set NTP (System > Settings or CLI). Clock skew breaks log integrity.
  2. Under Log Settings, choose disk / memory / FortiAnalyzer / syslog destinations.
  3. Decide severity and which log types are forwarded (All / Warning+ etc.).
  4. On critical firewall policies, enable Log Allowed Traffic and deny logging.
  5. Confirm VPN (SSL/IPsec) event logging: SSL VPN, Site-to-Site VPN.
  6. Send a test event to the central target; confirm it in Analyzer/SIEM.
  7. Watch disk quota and overwrite behavior—when full, older records are dropped.

Pro Tip: Do not start with “log everything to disk.” High traffic can fill local storage in hours. Strategy: short on-box retention + long central archive.

Disk, Syslog, and FortiAnalyzer

DestinationProsCons
Disk (on-box)Fast troubleshootingLimited space; no long retention
Syslog / SIEMCentral correlationNeeds format/parser work
FortiAnalyzerNative Fortinet reports/analyticsExtra license/appliance cost

For SIEM architecture, see SIEM, Syslog, and 5651 Architecture. For fabric visibility, see What Is Fortinet Security Fabric?. Analyzer/Manager line items belong in the purchase plan: Buying Guide.

How Policies Relate to Logs

Even with global logging enabled, traffic may stay invisible if the policy has logging disabled. Best practice:

  • Log on for every production allow
  • Explicit deny + log (visible default deny)
  • Even temporary any-any rules must log—then delete them

For ISO access-control evidence, see FortiGate Access Control for ISO 27001 and ISO 27001 Network Security.

5651, ISO 27001, and Retention

In Turkey, Law No. 5651 logging is not “something is recorded on the firewall.” Timestamping, retention, and identity/IP mapping matter. See What Is 5651 Logging? and Log Integrity in 5651 Compliance.

Practical split:

NeedFortiGate contributionAlso required
Operational troubleshootingTraffic/event logs
ISO 27001 monitoring evidenceCentral logs + retentionProcess/reporting
5651 evidentiary valueNAT/traffic log sourceTimestamping, archive, DHCP/identity

Define retention (for example ops 30-90 days, legal multi-year under 5651 frameworks) on Analyzer/SIEM. Archive strategy: 5651 Archiving.

Validation and Troubleshooting

  1. Do new traffic/event records appear under GUI Log & Report?
  2. On the syslog server, is the source IP the FortiGate management/log interface?
  3. Does the log line show the expected policy ID?
  4. Is NTP offset <1-2 seconds?
  5. Is disk usage climbing into overwrite?
  6. In HA, do both nodes log, or mainly the active? (HA)

For internet/NAT incidents, logs reveal the matched policy: No Internet Access, NAT Troubleshooting.

Most Common Mistakes

  • Leaving policy logging disabled
  • Expecting years of retention on local disk
  • Logging without NTP / wrong timezone
  • Enabling full debug logging and filling the disk
  • Sending syslog in clear text over the internet
  • Assuming “FortiGate logging on = 5651 compliant”

Related Articles

Checklist

  • NTP correct and monitored
  • Traffic/event/security destinations defined
  • Critical policies log allowed/denied
  • Central syslog or FortiAnalyzer tested
  • Disk quota and overwrite policy known
  • Retention (ops + compliance) written down
  • Log channel on management network / encrypted
  • HA log source behavior clarified

Next Step with LeonX

FortiGate logging makes the firewall auditable. Wrong destinations or silent policies blind both ops and compliance. LeonX designs FortiGate + syslog/Analyzer under Hardware and Software Solutions, especially Network Security, Firewall and IPS/IDS Solutions and SIEM and Security Incident Management Integration. For discovery, continue through Contact.

Frequently Asked Questions

How do you configure FortiGate logging?

Fix NTP, choose destinations (disk/syslog/Analyzer), enable logging on policies, and confirm records arrive centrally. On-box disk is not enough for long retention.

Which log types are required?

Traffic + event for operations; security for threat analysis. Compliance scope can widen—5651 often needs identity/DHCP/NAT layers too.

Is FortiAnalyzer mandatory?

No; syslog/SIEM works. FortiAnalyzer makes Fortinet-native reporting easier and needs its own license/appliance.

How long should logs be kept?

Ops often uses 30-90 days; legal/compliance needs (for example multi-year under 5651 frameworks) belong in a central archive. Write the policy down.

Do HA pairs double the logs?

Often the active unit dominates. Plan SIEM dedup and identify devices by hostname/serial.

Sources

Internal Link Path

Continue to the most relevant service pages

Use the links below to move from this article to the primary service, the most relevant detail page and the contact flow.

Share this article

Related Posts

Discover more on similar topics

FortiGate Logging ISO 27001 Requirements (2026 Guide)
Hardware & Software
2026-08-01
14 min read

FortiGate Logging ISO 27001 Requirements (2026 Guide)

FortiGate logging for ISO 27001: which logs, retention, integrity, access rights, reviews, and SoA evidence—with a practical checklist.

Read Article
How to Achieve ISO 27001 Network Security with FortiGate (2026)
Hardware & Software
2026-07-31
14 min read

How to Achieve ISO 27001 Network Security with FortiGate (2026)

Use FortiGate for ISO 27001 network security: segmentation, firewall policy, VPN, logging, admin hardening, and SoA evidence—with a practical checklist.

Read Article
KVKK-Compliant Network Security with FortiGate (2026 Guide)
Hardware & Software
2026-07-30
14 min read

KVKK-Compliant Network Security with FortiGate (2026 Guide)

How to use FortiGate for KVKK-aligned network security: segmentation, access control, VPN, logging, encryption balance, and a practical technical-controls checklist.

Read Article

Subscribe to Our Newsletter

Get the latest insights, trends, and expert advice delivered directly to your inbox. Join our community of IT professionals.

We respect your privacy. Unsubscribe at any time.