Fortinet black logo

CLI Reference

config log fortianalyzer3 setting

config log fortianalyzer3 setting

Global FortiAnalyzer settings.

config log fortianalyzer3 setting
    Description: Global FortiAnalyzer settings.
    set status [enable|disable]
    set ips-archive [enable|disable]
    set server {string}
    set hmac-algorithm [sha256|sha1]
    set enc-algorithm [high-medium|high|...]
    set conn-timeout {integer}
    set monitor-keepalive-period {integer}
    set monitor-failure-retry-period {integer}
    set certificate {string}
    set source-ip {string}
    set upload-option [store-and-upload|realtime|...]
    set upload-interval [daily|weekly|...]
    set upload-day {user}
    set upload-time {user}
    set reliable [enable|disable]
end

config log fortianalyzer3 setting

Parameter

Description

Type

Size

status

Enable/disable logging to FortiAnalyzer.

option

-

Option

Description

enable

Enable logging to FortiAnalyzer.

disable

Disable logging to FortiAnalyzer.

ips-archive

Enable/disable IPS packet archive logging.

option

-

Option

Description

enable

Enable IPS packet archive logging.

disable

Disable IPS packet archive logging.

server

The remote FortiAnalyzer.

string

Maximum length: 63

hmac-algorithm

FortiAnalyzer IPsec tunnel HMAC algorithm.

option

-

Option

Description

sha256

Use SHA256 as HMAC algorithm.

sha1

Step down to SHA1 as the HMAC algorithm.

enc-algorithm

Enable/disable sending FortiAnalyzer log data with SSL encryption.

option

-

Option

Description

high-medium

Encrypt logs using high and medium encryption algorithm.

high

Encrypt logs using high encryption algorithm.

low

Encrypt logs using low encryption algorithm.

disable

Disable SSL encryption.

conn-timeout

FortiAnalyzer connection time-out in seconds (for status and log buffer).

integer

Minimum value: 1 Maximum value: 3600

monitor-keepalive-period

Time between OFTP keepalives in seconds (for status and log buffer).

integer

Minimum value: 1 Maximum value: 120

monitor-failure-retry-period

Time between FortiAnalyzer connection retries in seconds (for status and log buffer).

integer

Minimum value: 1 Maximum value: 86400

certificate

Certificate used to communicate with FortiAnalyzer.

string

Maximum length: 35

source-ip

Source IPv4 or IPv6 address used to communicate with FortiAnalyzer.

string

Maximum length: 63

upload-option

Enable/disable logging to hard disk and then uploading to FortiAnalyzer.

option

-

Option

Description

store-and-upload

Log to hard disk and then upload to FortiAnalyzer.

realtime

Log directly to FortiAnalyzer in real time.

1-minute

Log directly to FortiAnalyzer at most every 1 minute.

5-minute

Log directly to FortiAnalyzer at most every 5 minutes.

upload-interval

Frequency to upload log files to FortiAnalyzer.

option

-

Option

Description

daily

Upload log files to FortiAnalyzer once a day.

weekly

Upload log files to FortiAnalyzer once a week.

monthly

Upload log files to FortiAnalyzer once a month.

upload-day

Day of week (month) to upload logs.

user

Not Specified

upload-time

Time to upload logs (hh:mm).

user

Not Specified

reliable

Enable/disable reliable logging to FortiAnalyzer.

option

-

Option

Description

enable

Enable reliable logging to FortiAnalyzer.

disable

Disable reliable logging to FortiAnalyzer.

config log fortianalyzer3 setting

Global FortiAnalyzer settings.

config log fortianalyzer3 setting
    Description: Global FortiAnalyzer settings.
    set status [enable|disable]
    set ips-archive [enable|disable]
    set server {string}
    set hmac-algorithm [sha256|sha1]
    set enc-algorithm [high-medium|high|...]
    set conn-timeout {integer}
    set monitor-keepalive-period {integer}
    set monitor-failure-retry-period {integer}
    set certificate {string}
    set source-ip {string}
    set upload-option [store-and-upload|realtime|...]
    set upload-interval [daily|weekly|...]
    set upload-day {user}
    set upload-time {user}
    set reliable [enable|disable]
end

config log fortianalyzer3 setting

Parameter

Description

Type

Size

status

Enable/disable logging to FortiAnalyzer.

option

-

Option

Description

enable

Enable logging to FortiAnalyzer.

disable

Disable logging to FortiAnalyzer.

ips-archive

Enable/disable IPS packet archive logging.

option

-

Option

Description

enable

Enable IPS packet archive logging.

disable

Disable IPS packet archive logging.

server

The remote FortiAnalyzer.

string

Maximum length: 63

hmac-algorithm

FortiAnalyzer IPsec tunnel HMAC algorithm.

option

-

Option

Description

sha256

Use SHA256 as HMAC algorithm.

sha1

Step down to SHA1 as the HMAC algorithm.

enc-algorithm

Enable/disable sending FortiAnalyzer log data with SSL encryption.

option

-

Option

Description

high-medium

Encrypt logs using high and medium encryption algorithm.

high

Encrypt logs using high encryption algorithm.

low

Encrypt logs using low encryption algorithm.

disable

Disable SSL encryption.

conn-timeout

FortiAnalyzer connection time-out in seconds (for status and log buffer).

integer

Minimum value: 1 Maximum value: 3600

monitor-keepalive-period

Time between OFTP keepalives in seconds (for status and log buffer).

integer

Minimum value: 1 Maximum value: 120

monitor-failure-retry-period

Time between FortiAnalyzer connection retries in seconds (for status and log buffer).

integer

Minimum value: 1 Maximum value: 86400

certificate

Certificate used to communicate with FortiAnalyzer.

string

Maximum length: 35

source-ip

Source IPv4 or IPv6 address used to communicate with FortiAnalyzer.

string

Maximum length: 63

upload-option

Enable/disable logging to hard disk and then uploading to FortiAnalyzer.

option

-

Option

Description

store-and-upload

Log to hard disk and then upload to FortiAnalyzer.

realtime

Log directly to FortiAnalyzer in real time.

1-minute

Log directly to FortiAnalyzer at most every 1 minute.

5-minute

Log directly to FortiAnalyzer at most every 5 minutes.

upload-interval

Frequency to upload log files to FortiAnalyzer.

option

-

Option

Description

daily

Upload log files to FortiAnalyzer once a day.

weekly

Upload log files to FortiAnalyzer once a week.

monthly

Upload log files to FortiAnalyzer once a month.

upload-day

Day of week (month) to upload logs.

user

Not Specified

upload-time

Time to upload logs (hh:mm).

user

Not Specified

reliable

Enable/disable reliable logging to FortiAnalyzer.

option

-

Option

Description

enable

Enable reliable logging to FortiAnalyzer.

disable

Disable reliable logging to FortiAnalyzer.