How to Configure FortiGate to Send Logs to FortiAnalyzer
A FortiGate administrator wants to integrate the FortiGate with a FortiAnalyzer for centralized logging. Which configuration step is required on the FortiGate?
Quick Answer
The correct answer is to enable 'Send Logs to FortiAnalyzer' under Log Settings and specify the FortiAnalyzer IP. This is required because FortiGate uses its proprietary logging protocol, not standard syslog, to securely forward logs to FortiAnalyzer for centralized management and analysis. On the Fortinet NSE 4 Network Security Professional NSE4 exam, this configuration step tests your understanding of native FortiGate-to-FortiAnalyzer integration, which does not require inbound firewall policies on the FortiGate—a common trap where candidates mistakenly think they need to open ports for incoming traffic. Remember, the FortiGate initiates the outbound log stream, so you only configure the destination IP under Log Settings. A useful memory tip: "Logs leave, they don't arrive"—the FortiGate sends logs out, so no inbound rules are needed.
⚠ Common exam trap
Test-takers frequently confuse native FortiAnalyzer logging with syslog, selecting Option B because they assume all log forwarding uses syslog, but FortiGate uses a proprietary protocol for FortiAnalyzer integration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable 'Send Logs to FortiAnalyzer' under Log Settings and specify the FortiAnalyzer IP
FortiGate integrates natively with FortiAnalyzer via the 'Send Logs to FortiAnalyzer' setting under Log Settings. This uses FortiGate's proprietary logging protocol (not syslog) to securely forward logs to the FortiAnalyzer IP, enabling centralized log management and analysis without additional firewall policies for inbound traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a firewall policy allowing traffic from FortiAnalyzer to the FortiGate
Why it's wrong here
Firewall policies may be needed but are not the primary configuration step.
- ✗
Configure a syslog server pointing to the FortiAnalyzer IP
Why it's wrong here
Syslog is not the native protocol; FortiGate uses proprietary FortiAnalyzer communication.
- ✓
Enable 'Send Logs to FortiAnalyzer' under Log Settings and specify the FortiAnalyzer IP
Why this is correct
This is the correct method to integrate with FortiAnalyzer.
- ✗
Configure an SNMP community on the FortiAnalyzer
Why it's wrong here
SNMP is for monitoring, not logging.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 282 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on NSE4
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An administrator needs to forward logs from a FortiGate to a FortiAnalyzer for centralized logging. The FortiAnalyzer IP is 10.10.10.10. Which configuration is required on the FortiGate?
medium- A.config system central-management set type fortianalyzer set ip 10.10.10.10 end
- B.config log setting set fortianalyzer ip 10.10.10.10 end
- C.config log syslogd setting set server 10.10.10.10 end
- ✓ D.config log fortianalyzer setting set status enable set server 10.10.10.10 end
Why D: The FortiGate uses the `config log fortianalyzer setting` command to configure direct logging to a FortiAnalyzer. This command enables the log forwarding feature (`set status enable`) and specifies the FortiAnalyzer's IP address (`set server 10.10.10.10`). The other options either use incorrect command paths or are intended for different logging destinations (e.g., syslog or central management).
Variation 2. An administrator wants to send FortiGate logs to a FortiAnalyzer for centralized logging and reporting. Which configuration step is required on the FortiGate?
medium- A.Enable SNMP traps to the FortiAnalyzer
- B.Create a firewall policy to allow traffic to the FortiAnalyzer
- ✓ C.Under Log & Report, configure the FortiAnalyzer settings and set the log forwarding
- D.Configure a syslog server under System > Settings
Why C: FortiGate uses the Log & Report section to configure FortiAnalyzer settings, specifically under 'Log Settings' or 'Log Forwarding'. This enables the FortiGate to forward logs to a FortiAnalyzer device for centralized logging and reporting, using the FortiGate-FortiAnalyzer protocol (based on syslog over TCP with Fortinet extensions).
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.