How to Configure FortiGate to Send Logs to FortiAnalyzer
An administrator wants to send FortiGate logs to a FortiAnalyzer for centralized logging and reporting. Which configuration step is required on the FortiGate?
⚠ Common exam trap
It's easy for candidates to confuse the generic syslog server configuration (Option D) with the FortiAnalyzer-specific log forwarding setup, or they mistakenly think a firewall policy (Option B) is the primary step rather than the log forwarding configuration itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Under Log & Report, configure the FortiAnalyzer settings and set the log forwarding
FortiGate uses the Log & Report section to configure FortiAnalyzer settings, specifically under 'Log Settings' or 'Log Forwarding'. This enables the FortiGate to forward logs to a FortiAnalyzer device for centralized logging and reporting, using the FortiGate-FortiAnalyzer protocol (based on syslog over TCP with Fortinet extensions).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable SNMP traps to the FortiAnalyzer
Why it's wrong here
SNMP traps are a monitoring mechanism, not a log-forwarding method. FortiGate uses SNMP to send alert messages about device health or discrete events to an SNMP manager, which lacks the structured, full-fidelity log records (e.g., traffic sessions, threat logs) that FortiAnalyzer needs. Moreover, FortiAnalyzer receives logs via the proprietary FGFM protocol or other specific settings under Log & Report, not via SNMP traps. Thus, enabling SNMP traps would only convey status notifications and would never deliver the comprehensive logging expected by FortiAnalyzer.
- ✗
Create a firewall policy to allow traffic to the FortiAnalyzer
Why it's wrong here
While a firewall policy is essential to establish network connectivity between FortiGate and FortiAnalyzer, creating one does not cause log forwarding to occur. Log forwarding is an application-layer configuration: you must explicitly define the FortiAnalyzer as a log destination and enable log transmission in the Log & Report section. Without that explicit setting, FortiGate will continue to store logs locally, even if traffic passes freely. Therefore, the firewall policy is a necessary prerequisite but not the specific action to send logs to FortiAnalyzer.
- ✓
Under Log & Report, configure the FortiAnalyzer settings and set the log forwarding
Why this is correct
This is the correct action because FortiGate has dedicated integration settings for FortiAnalyzer under the Log & Report menu (often System > Log & Report > FortiAnalyzer). Here, you enter the FortiAnalyzer IP/FQDN and serial number, and then enable log sending/archiving for specific log types (e.g., traffic, event). Once configured, FortiGate uses the FGFM (FortiGate-to-FortiAnalyzer) protocol to securely and reliably forward logs, including buffering and retransmission. This is the intended mechanism for centralized logging on FortiAnalyzer, so this option precisely addresses the administrator's goal.
- ✗
Configure a syslog server under System > Settings
Why it's wrong here
Configuring a syslog server under System > Settings is incorrect because Syslog is a generic, text-based logging protocol, not the native FortiAnalyzer communication method. FortiAnalyzer uses the proprietary FGFM protocol for full integration, which includes the FortiGate serial number registration, compressed binary logs, and reliable delivery; Syslog lacks these features and would send untagged, unstructured data. Additionally, the actual syslog configuration in FortiGate is found under Log & Report, not System > Settings. Hence, using Syslog would not properly tie into FortiAnalyzer's indexing and reporting, and it is the wrong tool for this task.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on NSE4
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An administrator needs to forward logs from a FortiGate to a FortiAnalyzer for centralized logging. The FortiAnalyzer IP is 10.10.10.10. Which configuration is required on the FortiGate?
medium- A.config system central-management set type fortianalyzer set ip 10.10.10.10 end
- B.config log setting set fortianalyzer ip 10.10.10.10 end
- C.config log syslogd setting set server 10.10.10.10 end
- ✓ D.config log fortianalyzer setting set status enable set server 10.10.10.10 end
Why D: The FortiGate uses the `config log fortianalyzer setting` command to configure direct logging to a FortiAnalyzer. This command enables the log forwarding feature (`set status enable`) and specifies the FortiAnalyzer's IP address (`set server 10.10.10.10`). The other options either use incorrect command paths or are intended for different logging destinations (e.g., syslog or central management).
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.