Fortinet black logo

CLI Reference

config log fortianalyzer override-setting

config log fortianalyzer override-setting

Override FortiAnalyzer settings.

config log fortianalyzer override-setting
    Description: Override FortiAnalyzer settings.
    set override [enable|disable]
    set use-management-vdom [enable|disable]
    set status [enable|disable]
    set ips-archive [enable|disable]
    set server {string}
    set hmac-algorithm [sha256|sha1]
    set enc-algorithm [high-medium|high|...]
    set conn-timeout {integer}
    set monitor-keepalive-period {integer}
    set monitor-failure-retry-period {integer}
    set certificate {string}
    set source-ip {string}
    set upload-option [store-and-upload|realtime|...]
    set upload-interval [daily|weekly|...]
    set upload-day {user}
    set upload-time {user}
    set reliable [enable|disable]
end

config log fortianalyzer override-setting

Parameter

Description

Type

Size

override

Enable/disable overriding FortiAnalyzer settings or use global settings.

option

-

Option

Description

enable

Override FortiAnalyzer.

disable

Do not override FortiAnalyzer.

use-management-vdom

Enable/disable use of management VDOM IP address as source IP for logs sent to FortiAnalyzer.

option

-

Option

Description

enable

Enable use of management VDOM IP address as source IP for logs sent to FortiAnalyzer.

disable

Disable use of management VDOM IP address as source IP for logs sent to FortiAnalyzer.

status

Enable/disable logging to FortiAnalyzer.

option

-

Option

Description

enable

Enable logging to FortiAnalyzer.

disable

Disable logging to FortiAnalyzer.

ips-archive

Enable/disable IPS packet archive logging.

option

-

Option

Description

enable

Enable IPS packet archive logging.

disable

Disable IPS packet archive logging.

server

The remote FortiAnalyzer.

string

Maximum length: 63

hmac-algorithm

FortiAnalyzer IPsec tunnel HMAC algorithm.

option

-

Option

Description

sha256

Use SHA256 as HMAC algorithm.

sha1

Step down to SHA1 as the HMAC algorithm.

enc-algorithm

Enable/disable sending FortiAnalyzer log data with SSL encryption.

option

-

Option

Description

high-medium

Encrypt logs using high and medium encryption algorithm.

high

Encrypt logs using high encryption algorithm.

low

Encrypt logs using low encryption algorithm.

disable

Disable SSL encryption.

conn-timeout

FortiAnalyzer connection time-out in seconds (for status and log buffer).

integer

Minimum value: 1 Maximum value: 3600

monitor-keepalive-period

Time between OFTP keepalives in seconds (for status and log buffer).

integer

Minimum value: 1 Maximum value: 120

monitor-failure-retry-period

Time between FortiAnalyzer connection retries in seconds (for status and log buffer).

integer

Minimum value: 1 Maximum value: 86400

certificate

Certificate used to communicate with FortiAnalyzer.

string

Maximum length: 35

source-ip

Source IPv4 or IPv6 address used to communicate with FortiAnalyzer.

string

Maximum length: 63

upload-option

Enable/disable logging to hard disk and then uploading to FortiAnalyzer.

option

-

Option

Description

store-and-upload

Log to hard disk and then upload to FortiAnalyzer.

realtime

Log directly to FortiAnalyzer in real time.

1-minute

Log directly to FortiAnalyzer at most every 1 minute.

5-minute

Log directly to FortiAnalyzer at most every 5 minutes.

upload-interval

Frequency to upload log files to FortiAnalyzer.

option

-

Option

Description

daily

Upload log files to FortiAnalyzer once a day.

weekly

Upload log files to FortiAnalyzer once a week.

monthly

Upload log files to FortiAnalyzer once a month.

upload-day

Day of week (month) to upload logs.

user

Not Specified

upload-time

Time to upload logs (hh:mm).

user

Not Specified

reliable

Enable/disable reliable logging to FortiAnalyzer.

option

-

Option

Description

enable

Enable reliable logging to FortiAnalyzer.

disable

Disable reliable logging to FortiAnalyzer.

config log fortianalyzer override-setting

Override FortiAnalyzer settings.

config log fortianalyzer override-setting
    Description: Override FortiAnalyzer settings.
    set override [enable|disable]
    set use-management-vdom [enable|disable]
    set status [enable|disable]
    set ips-archive [enable|disable]
    set server {string}
    set hmac-algorithm [sha256|sha1]
    set enc-algorithm [high-medium|high|...]
    set conn-timeout {integer}
    set monitor-keepalive-period {integer}
    set monitor-failure-retry-period {integer}
    set certificate {string}
    set source-ip {string}
    set upload-option [store-and-upload|realtime|...]
    set upload-interval [daily|weekly|...]
    set upload-day {user}
    set upload-time {user}
    set reliable [enable|disable]
end

config log fortianalyzer override-setting

Parameter

Description

Type

Size

override

Enable/disable overriding FortiAnalyzer settings or use global settings.

option

-

Option

Description

enable

Override FortiAnalyzer.

disable

Do not override FortiAnalyzer.

use-management-vdom

Enable/disable use of management VDOM IP address as source IP for logs sent to FortiAnalyzer.

option

-

Option

Description

enable

Enable use of management VDOM IP address as source IP for logs sent to FortiAnalyzer.

disable

Disable use of management VDOM IP address as source IP for logs sent to FortiAnalyzer.

status

Enable/disable logging to FortiAnalyzer.

option

-

Option

Description

enable

Enable logging to FortiAnalyzer.

disable

Disable logging to FortiAnalyzer.

ips-archive

Enable/disable IPS packet archive logging.

option

-

Option

Description

enable

Enable IPS packet archive logging.

disable

Disable IPS packet archive logging.

server

The remote FortiAnalyzer.

string

Maximum length: 63

hmac-algorithm

FortiAnalyzer IPsec tunnel HMAC algorithm.

option

-

Option

Description

sha256

Use SHA256 as HMAC algorithm.

sha1

Step down to SHA1 as the HMAC algorithm.

enc-algorithm

Enable/disable sending FortiAnalyzer log data with SSL encryption.

option

-

Option

Description

high-medium

Encrypt logs using high and medium encryption algorithm.

high

Encrypt logs using high encryption algorithm.

low

Encrypt logs using low encryption algorithm.

disable

Disable SSL encryption.

conn-timeout

FortiAnalyzer connection time-out in seconds (for status and log buffer).

integer

Minimum value: 1 Maximum value: 3600

monitor-keepalive-period

Time between OFTP keepalives in seconds (for status and log buffer).

integer

Minimum value: 1 Maximum value: 120

monitor-failure-retry-period

Time between FortiAnalyzer connection retries in seconds (for status and log buffer).

integer

Minimum value: 1 Maximum value: 86400

certificate

Certificate used to communicate with FortiAnalyzer.

string

Maximum length: 35

source-ip

Source IPv4 or IPv6 address used to communicate with FortiAnalyzer.

string

Maximum length: 63

upload-option

Enable/disable logging to hard disk and then uploading to FortiAnalyzer.

option

-

Option

Description

store-and-upload

Log to hard disk and then upload to FortiAnalyzer.

realtime

Log directly to FortiAnalyzer in real time.

1-minute

Log directly to FortiAnalyzer at most every 1 minute.

5-minute

Log directly to FortiAnalyzer at most every 5 minutes.

upload-interval

Frequency to upload log files to FortiAnalyzer.

option

-

Option

Description

daily

Upload log files to FortiAnalyzer once a day.

weekly

Upload log files to FortiAnalyzer once a week.

monthly

Upload log files to FortiAnalyzer once a month.

upload-day

Day of week (month) to upload logs.

user

Not Specified

upload-time

Time to upload logs (hh:mm).

user

Not Specified

reliable

Enable/disable reliable logging to FortiAnalyzer.

option

-

Option

Description

enable

Enable reliable logging to FortiAnalyzer.

disable

Disable reliable logging to FortiAnalyzer.