Fortinet FortiGate: send syslog, NetFlow, sFlow and SNMP traps to MobiObs
A FortiGate can send its traffic and event logs as syslog or CEF, export NetFlow and sFlow, and raise SNMP traps, all with a configurable destination port. This guide sets each one up towards a MobiObs device, shows how to check it and how to take it out again.
MobiObs is not released yet. It is coming to Google Play first, then the App Store and desktop. Join the launch list to get one email when it is available.
Before you start
The examples send to a MobiObs device at 10.20.4.9 from the FortiGate address 192.0.2.4. MobiObs listens on udp/5514 and tcp/5514 for syslog, udp/2055 for NetFlow, udp/6343 for sFlow and udp/1162 for traps; a mobile app cannot bind 514 or 162.
Commands are for FortiOS 7.x in the CLI console. Several options moved between 7.0, 7.2 and 7.4, and each block is labelled with the release it was written for. If a set is rejected, press ? to list what your build accepts. On a FortiGate with VDOMs, syslog and NetFlow can also be configured per VDOM under config vdom.
Syslog and CEF
FortiOS 7.0+: syslog to 10.20.4.9
config log syslogd setting
set status enable
set server "10.20.4.9"
set port 5514
set mode udp
set format rfc5424
set facility local7
set source-ip 192.0.2.4
end
config log syslogd filter
set severity information
set forward-traffic enable
set local-traffic disable
end
mode:udpis plain UDP.reliablesends over TCP, framed per RFC 6587, which MobiObs detects automatically on tcp/5514.legacy-reliableis an older TCP framing; preferreliable.format:defaultsends FortiGate key=value messages,csvcomma-separated values,cefArcSight CEF andrfc5424structured syslog. MobiObs extracts CEF vendor, product, signature and extension fields, socefgives the most filterable result.rfc5424is not offered on early 7.0 builds.- Existing servers: if
syslogdalready points at your SIEM, leave it alone and useconfig log syslogd2 setting(orsyslogd3,syslogd4) for MobiObs. Each has its own filter.
Forward-traffic logs are only written for policies with logging enabled (set logtraffic all, or utm for security events only), and they can be high volume on a busy firewall. Enable them for a limited time or on the policies you are investigating.
NetFlow
FortiGate exports NetFlow v9. From FortiOS 7.4 the collectors are a table; up to 7.2 the collector is set directly.
FortiOS 7.4+: NetFlow v9 to udp/2055
config system netflow
config collectors
edit 1
set collector-ip "10.20.4.9"
set collector-port 2055
set source-ip 192.0.2.4
next
end
end
config system interface
edit "port1"
set netflow-sampler both
next
end
FortiOS 7.0 / 7.2: NetFlow v9 to udp/2055
config system netflow
set collector-ip 10.20.4.9
set collector-port 2055
set source-ip 192.0.2.4
end
netflow-sampler accepts tx, rx or both. The active and inactive flow timeouts and the template refresh interval are also under config system netflow; their units and ranges differ between releases, so check them with ?. Flows offloaded to an NP processor may not be exported on every model; see Fortinet's hardware acceleration guide for your platform.
sFlow
FortiOS 7.0 / 7.2: sFlow to udp/6343
config system sflow
set collector-ip 10.20.4.9
set collector-port 6343
set source-ip 192.0.2.4
end
config system interface
edit "port1"
set sflow-sampler enable
set sample-rate 2000
set sample-direction both
set polling-interval 20
next
end
Later releases also moved sFlow collectors into a config collectors table, like NetFlow; verify on your release. Use either NetFlow or sFlow on an interface, not both, to avoid counting the same traffic twice.
SNMP traps (v2c and v3)
FortiOS 7.x: SNMPv2c community with a trap host on udp/1162
config system snmp sysinfo
set status enable
end
config system snmp community
edit 10
set name "MOBIOBS-RO"
set trap-v2c-rport 1162
config hosts
edit 1
set ip 10.20.4.9 255.255.255.255
set host-type trap
next
end
next
end
FortiOS 7.x: SNMPv3 authPriv user sending traps to udp/1162
config system snmp user
edit "mobiobs"
set notify-hosts 10.20.4.9
set trap-rport 1162
set security-level auth-priv
set auth-proto sha256
set auth-pwd AuthPass-change-me
set priv-proto aes
set priv-pwd PrivPass-change-me
next
end
Pick a community ID (edit 10) that is not already in use. Enter the same community, or the same SNMPv3 user and protocols, in MobiObs; SNMPv3 users are a Pro feature. Which events raise traps is controlled by set events on the community or user.
Verify on the device
FortiOS: checks and a packet capture
diagnose log test
diagnose sniffer packet any 'host 10.20.4.9' 4 20
get log syslogd setting
show system netflow
show system snmp community
diagnose log test writes a set of sample log entries, which should appear in MobiObs within seconds. The sniffer shows whether packets actually leave the FortiGate towards the device and from which interface. If they leave but never arrive, follow the troubleshooting checklist.
Remove it afterwards
FortiOS: clean-up
config log syslogd setting
set status disable
end
config system interface
edit "port1"
set netflow-sampler disable
set sflow-sampler disable
next
end
config system snmp community
delete 10
end
config system snmp user
delete "mobiobs"
end
If you used syslogd2 or later, disable that one instead. On 7.4, also delete 1 under config system netflow → config collectors. FortiOS saves changes as soon as each end is entered, so there is no separate save step.