Courseiva
System and Network AdministrationmediumMultiple ChoiceObjective-mapped

How to Configure FortiGate to Send Logs to FortiAnalyzer

A FortiGate administrator wants to integrate the FortiGate with a FortiAnalyzer for centralized logging. Which configuration step is required on the FortiGate?

Quick Answer

The correct answer is to enable 'Send Logs to FortiAnalyzer' under Log Settings and specify the FortiAnalyzer IP. This is required because FortiGate uses its proprietary logging protocol, not standard syslog, to securely forward logs to FortiAnalyzer for centralized management and analysis. On the Fortinet NSE 4 Network Security Professional NSE4 exam, this configuration step tests your understanding of native FortiGate-to-FortiAnalyzer integration, which does not require inbound firewall policies on the FortiGate—a common trap where candidates mistakenly think they need to open ports for incoming traffic. Remember, the FortiGate initiates the outbound log stream, so you only configure the destination IP under Log Settings. A useful memory tip: "Logs leave, they don't arrive"—the FortiGate sends logs out, so no inbound rules are needed.

⚠ Common exam trap

Test-takers frequently confuse native FortiAnalyzer logging with syslog, selecting Option B because they assume all log forwarding uses syslog, but FortiGate uses a proprietary protocol for FortiAnalyzer integration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Enable 'Send Logs to FortiAnalyzer' under Log Settings and specify the FortiAnalyzer IP

FortiGate integrates natively with FortiAnalyzer via the 'Send Logs to FortiAnalyzer' setting under Log Settings. This uses FortiGate's proprietary logging protocol (not syslog) to securely forward logs to the FortiAnalyzer IP, enabling centralized log management and analysis without additional firewall policies for inbound traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create a firewall policy allowing traffic from FortiAnalyzer to the FortiGate

    Why it's wrong here

    Firewall policies may be needed but are not the primary configuration step.

  • Configure a syslog server pointing to the FortiAnalyzer IP

    Why it's wrong here

    Syslog is not the native protocol; FortiGate uses proprietary FortiAnalyzer communication.

  • Enable 'Send Logs to FortiAnalyzer' under Log Settings and specify the FortiAnalyzer IP

    Why this is correct

    This is the correct method to integrate with FortiAnalyzer.

  • Configure an SNMP community on the FortiAnalyzer

    Why it's wrong here

    SNMP is for monitoring, not logging.

About these practice questions

Courseiva writes every NSE4 question from scratch — 282 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on NSE4

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An administrator needs to forward logs from a FortiGate to a FortiAnalyzer for centralized logging. The FortiAnalyzer IP is 10.10.10.10. Which configuration is required on the FortiGate?

medium
  • A.config system central-management set type fortianalyzer set ip 10.10.10.10 end
  • B.config log setting set fortianalyzer ip 10.10.10.10 end
  • C.config log syslogd setting set server 10.10.10.10 end
  • D.config log fortianalyzer setting set status enable set server 10.10.10.10 end

Why D: The FortiGate uses the `config log fortianalyzer setting` command to configure direct logging to a FortiAnalyzer. This command enables the log forwarding feature (`set status enable`) and specifies the FortiAnalyzer's IP address (`set server 10.10.10.10`). The other options either use incorrect command paths or are intended for different logging destinations (e.g., syslog or central management).

Variation 2. An administrator wants to send FortiGate logs to a FortiAnalyzer for centralized logging and reporting. Which configuration step is required on the FortiGate?

medium
  • A.Enable SNMP traps to the FortiAnalyzer
  • B.Create a firewall policy to allow traffic to the FortiAnalyzer
  • C.Under Log & Report, configure the FortiAnalyzer settings and set the log forwarding
  • D.Configure a syslog server under System > Settings

Why C: FortiGate uses the Log & Report section to configure FortiAnalyzer settings, specifically under 'Log Settings' or 'Log Forwarding'. This enables the FortiGate to forward logs to a FortiAnalyzer device for centralized logging and reporting, using the FortiGate-FortiAnalyzer protocol (based on syslog over TCP with Fortinet extensions).

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.