Connecting FortiGate to Logmanager is useful because it centralizes traffic events, security logs, and operational activity from the firewall in one searchable platform. Once the source is configured correctly, Logmanager can parse incoming FortiGate data automatically and expose it through built-in dashboards.

Prefer watching?

Check the related video walkthrough:

1. Prepare the Source Definition

In Logmanager, open the relevant source configuration area and review the FortiGate instructions. Then go to Processing Tools → IP Prefix List, find the predefined FortiGate template, and add the IP address of the FortiGate device.

IP Prefix List in Logmanager showing the predefined FortiGate template and device IP configuration
Fig. 1: IP Prefix List in Logmanager showing the predefined FortiGate template and device IP configuration.

2. Find the Logmanager Destination IP

Open your Logmanager instance page and copy the IP address that the firewall should use as its logging destination.

3. Enable Logging on FortiGate

In the FortiGate web interface, open Log & Report → Log Settings. Enable the appropriate logging method, paste the Logmanager IP address, and apply the settings.

FortiGate log settings page configured to send logs to the Logmanager destination IP
Fig. 2: FortiGate log settings page configured to send logs to the Logmanager destination IP.

4. Verify Incoming Events

Once the integration is active, open the predefined FortiGate dashboards or your default dashboard and filter by FortiGate. You should see incoming events and be able to inspect both processed and raw logs.

Logmanager dashboard displaying incoming FortiGate logs after successful integration
Fig. 3: Logmanager dashboard displaying incoming FortiGate logs after successful integration.