Fortinet FortiGate: send syslog, NetFlow, sFlow and SNMP traps to MobiObs

Updated 28 September 2026

A FortiGate can send its traffic and event logs as syslog or CEF, export NetFlow and sFlow, and raise SNMP traps, all with a configurable destination port. This guide sets each one up towards a MobiObs device, shows how to check it and how to take it out again.

MobiObs is not released yet. It is coming to Google Play first, then the App Store and desktop. Join the launch list to get one email when it is available.

Before you start

The examples send to a MobiObs device at 10.20.4.9 from the FortiGate address 192.0.2.4. MobiObs listens on udp/5514 and tcp/5514 for syslog, udp/2055 for NetFlow, udp/6343 for sFlow and udp/1162 for traps; a mobile app cannot bind 514 or 162.

Commands are for FortiOS 7.x in the CLI console. Several options moved between 7.0, 7.2 and 7.4, and each block is labelled with the release it was written for. If a set is rejected, press ? to list what your build accepts. On a FortiGate with VDOMs, syslog and NetFlow can also be configured per VDOM under config vdom.

Syslog and CEF

FortiOS 7.0+: syslog to 10.20.4.9

config log syslogd setting
    set status enable
    set server "10.20.4.9"
    set port 5514
    set mode udp
    set format rfc5424
    set facility local7
    set source-ip 192.0.2.4
end
config log syslogd filter
    set severity information
    set forward-traffic enable
    set local-traffic disable
end
  • mode: udp is plain UDP. reliable sends over TCP, framed per RFC 6587, which MobiObs detects automatically on tcp/5514. legacy-reliable is an older TCP framing; prefer reliable.
  • format: default sends FortiGate key=value messages, csv comma-separated values, cef ArcSight CEF and rfc5424 structured syslog. MobiObs extracts CEF vendor, product, signature and extension fields, so cef gives the most filterable result. rfc5424 is not offered on early 7.0 builds.
  • Existing servers: if syslogd already points at your SIEM, leave it alone and use config log syslogd2 setting (or syslogd3, syslogd4) for MobiObs. Each has its own filter.

Forward-traffic logs are only written for policies with logging enabled (set logtraffic all, or utm for security events only), and they can be high volume on a busy firewall. Enable them for a limited time or on the policies you are investigating.

NetFlow

FortiGate exports NetFlow v9. From FortiOS 7.4 the collectors are a table; up to 7.2 the collector is set directly.

FortiOS 7.4+: NetFlow v9 to udp/2055

config system netflow
    config collectors
        edit 1
            set collector-ip "10.20.4.9"
            set collector-port 2055
            set source-ip 192.0.2.4
        next
    end
end
config system interface
    edit "port1"
        set netflow-sampler both
    next
end

FortiOS 7.0 / 7.2: NetFlow v9 to udp/2055

config system netflow
    set collector-ip 10.20.4.9
    set collector-port 2055
    set source-ip 192.0.2.4
end

netflow-sampler accepts tx, rx or both. The active and inactive flow timeouts and the template refresh interval are also under config system netflow; their units and ranges differ between releases, so check them with ?. Flows offloaded to an NP processor may not be exported on every model; see Fortinet's hardware acceleration guide for your platform.

sFlow

FortiOS 7.0 / 7.2: sFlow to udp/6343

config system sflow
    set collector-ip 10.20.4.9
    set collector-port 6343
    set source-ip 192.0.2.4
end
config system interface
    edit "port1"
        set sflow-sampler enable
        set sample-rate 2000
        set sample-direction both
        set polling-interval 20
    next
end

Later releases also moved sFlow collectors into a config collectors table, like NetFlow; verify on your release. Use either NetFlow or sFlow on an interface, not both, to avoid counting the same traffic twice.

SNMP traps (v2c and v3)

FortiOS 7.x: SNMPv2c community with a trap host on udp/1162

config system snmp sysinfo
    set status enable
end
config system snmp community
    edit 10
        set name "MOBIOBS-RO"
        set trap-v2c-rport 1162
        config hosts
            edit 1
                set ip 10.20.4.9 255.255.255.255
                set host-type trap
            next
        end
    next
end

FortiOS 7.x: SNMPv3 authPriv user sending traps to udp/1162

config system snmp user
    edit "mobiobs"
        set notify-hosts 10.20.4.9
        set trap-rport 1162
        set security-level auth-priv
        set auth-proto sha256
        set auth-pwd AuthPass-change-me
        set priv-proto aes
        set priv-pwd PrivPass-change-me
    next
end

Pick a community ID (edit 10) that is not already in use. Enter the same community, or the same SNMPv3 user and protocols, in MobiObs; SNMPv3 users are a Pro feature. Which events raise traps is controlled by set events on the community or user.

Verify on the device

FortiOS: checks and a packet capture

diagnose log test
diagnose sniffer packet any 'host 10.20.4.9' 4 20
get log syslogd setting
show system netflow
show system snmp community

diagnose log test writes a set of sample log entries, which should appear in MobiObs within seconds. The sniffer shows whether packets actually leave the FortiGate towards the device and from which interface. If they leave but never arrive, follow the troubleshooting checklist.

Remove it afterwards

FortiOS: clean-up

config log syslogd setting
    set status disable
end
config system interface
    edit "port1"
        set netflow-sampler disable
        set sflow-sampler disable
    next
end
config system snmp community
    delete 10
end
config system snmp user
    delete "mobiobs"
end

If you used syslogd2 or later, disable that one instead. On 7.4, also delete 1 under config system netflow → config collectors. FortiOS saves changes as soon as each end is entered, so there is no separate save step.