7.2.1 Centralized Logging and Reporting

Information

Device logs should be sent to a centralized device for log collection, retention, and reporting. This could be a SIEM. syslog device, FortiAnalyzer, FortiManager, etc.

Centralized logging allows for more reliable log retention and more enriched log data for review and reporting.

Solution

Configure a remote server for logs to be sent to:

1. Go to Log & Report > Log Settings.
2. Under \\"Syslog logging\\" configure a remote server to send logs to.

See Also

https://workbench.cisecurity.org/benchmarks/24708

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-1, 800-53|AU-2, 800-53|AU-6(3), CSCv7|6.3, CSCv7|8.6

Plugin: FortiGate

Control ID: e814c65b0a2bddaeb945173f8096cdbee719f68a1d575bc2c179b755d6041d36