Courseiva

How to Configure FortiGate to Send Logs to FortiAnalyzer

An administrator wants to send FortiGate logs to a FortiAnalyzer for centralized logging and reporting. Which configuration step is required on the FortiGate?

⚠ Common exam trap

It's easy for candidates to confuse the generic syslog server configuration (Option D) with the FortiAnalyzer-specific log forwarding setup, or they mistakenly think a firewall policy (Option B) is the primary step rather than the log forwarding configuration itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Under Log & Report, configure the FortiAnalyzer settings and set the log forwarding

FortiGate uses the Log & Report section to configure FortiAnalyzer settings, specifically under 'Log Settings' or 'Log Forwarding'. This enables the FortiGate to forward logs to a FortiAnalyzer device for centralized logging and reporting, using the FortiGate-FortiAnalyzer protocol (based on syslog over TCP with Fortinet extensions).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable SNMP traps to the FortiAnalyzer

    Why it's wrong here

    SNMP traps are a monitoring mechanism, not a log-forwarding method. FortiGate uses SNMP to send alert messages about device health or discrete events to an SNMP manager, which lacks the structured, full-fidelity log records (e.g., traffic sessions, threat logs) that FortiAnalyzer needs. Moreover, FortiAnalyzer receives logs via the proprietary FGFM protocol or other specific settings under Log & Report, not via SNMP traps. Thus, enabling SNMP traps would only convey status notifications and would never deliver the comprehensive logging expected by FortiAnalyzer.

  • ✗

    Create a firewall policy to allow traffic to the FortiAnalyzer

    Why it's wrong here

    While a firewall policy is essential to establish network connectivity between FortiGate and FortiAnalyzer, creating one does not cause log forwarding to occur. Log forwarding is an application-layer configuration: you must explicitly define the FortiAnalyzer as a log destination and enable log transmission in the Log & Report section. Without that explicit setting, FortiGate will continue to store logs locally, even if traffic passes freely. Therefore, the firewall policy is a necessary prerequisite but not the specific action to send logs to FortiAnalyzer.

  • ✓

    Under Log & Report, configure the FortiAnalyzer settings and set the log forwarding

    Why this is correct

    This is the correct action because FortiGate has dedicated integration settings for FortiAnalyzer under the Log & Report menu (often System > Log & Report > FortiAnalyzer). Here, you enter the FortiAnalyzer IP/FQDN and serial number, and then enable log sending/archiving for specific log types (e.g., traffic, event). Once configured, FortiGate uses the FGFM (FortiGate-to-FortiAnalyzer) protocol to securely and reliably forward logs, including buffering and retransmission. This is the intended mechanism for centralized logging on FortiAnalyzer, so this option precisely addresses the administrator's goal.

  • ✗

    Configure a syslog server under System > Settings

    Why it's wrong here

    Configuring a syslog server under System > Settings is incorrect because Syslog is a generic, text-based logging protocol, not the native FortiAnalyzer communication method. FortiAnalyzer uses the proprietary FGFM protocol for full integration, which includes the FortiGate serial number registration, compressed binary logs, and reliable delivery; Syslog lacks these features and would send untagged, unstructured data. Additionally, the actual syslog configuration in FortiGate is found under Log & Report, not System > Settings. Hence, using Syslog would not properly tie into FortiAnalyzer's indexing and reporting, and it is the wrong tool for this task.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on NSE4

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An administrator needs to forward logs from a FortiGate to a FortiAnalyzer for centralized logging. The FortiAnalyzer IP is 10.10.10.10. Which configuration is required on the FortiGate?

medium
  • A.config system central-management set type fortianalyzer set ip 10.10.10.10 end
  • B.config log setting set fortianalyzer ip 10.10.10.10 end
  • C.config log syslogd setting set server 10.10.10.10 end
  • ✓ D.config log fortianalyzer setting set status enable set server 10.10.10.10 end

Why D: The FortiGate uses the `config log fortianalyzer setting` command to configure direct logging to a FortiAnalyzer. This command enables the log forwarding feature (`set status enable`) and specifies the FortiAnalyzer's IP address (`set server 10.10.10.10`). The other options either use incorrect command paths or are intended for different logging destinations (e.g., syslog or central management).

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.