# Fortigate 30E not sending any logs to ubuntu/logstash

**URL:** <https://discuss.elastic.co/t/fortigate-30e-not-sending-any-logs-to-ubuntu-logstash/352270>\
**Category:** Logstash\
**Created:** [February 1, 2024, 9:59am UTC](https://discuss.elastic.co/t/fortigate-30e-not-sending-any-logs-to-ubuntu-logstash/352270 "2024-02-01T09:59:30Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![dadafaf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadafaf/32/131317_2.png) [@dadafaf](https://discuss.elastic.co/u/dadafaf)\
**Post date:** [February 1, 2024, 9:59am UTC](https://discuss.elastic.co/t/fortigate-30e-not-sending-any-logs-to-ubuntu-logstash/352270/1 "2024-02-01T09:59:30Z")

</div>

Hi!

I have a problem that I need help with. I am using a Fortigate 30e firewall and a log server on a virtual machine with ELK stack and Logstash installed. The goal is to send logs from the Fortigate 30e to the log server's Logstash, and from there to Elasticsearch and then visualize them in Kibana.

I have configured the port 5144/udp and the log server's IP (Logstash's IP) from the Fortigate management panel. On the Ubuntu side, traffic has been allowed through the firewall. The port has been checked and is free to use.

The problem is that no logs are coming through to the log server or appearing in the log files /var/log/logstash-plain.log or /var/log/syslog. I have connected the WAN network from the internet cable \> to the firewall \> from the firewall to the switch \> from the switch to a laptop that contains VMware and the log server virtual machine.

Ask if you need more information and thanks for the help.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 1, 2024, 10:15am UTC](https://discuss.elastic.co/t/fortigate-30e-not-sending-any-logs-to-ubuntu-logstash/352270/2 "2024-02-01T10:15:19Z")

</div>

Can you share your Logstash configuration?

This seems like a network issue, if Logstash is listening on the correct port and IP and you still do not get any logs, you need to check if everything is ok in the network, there is not much else to do in Logstash side.

---

<div class="post-metadata">

**Author:** ![dadafaf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadafaf/32/131317_2.png) [@dadafaf](https://discuss.elastic.co/u/dadafaf)\
**Post date:** [February 1, 2024, 10:34am UTC](https://discuss.elastic.co/t/fortigate-30e-not-sending-any-logs-to-ubuntu-logstash/352270/3 "2024-02-01T10:34:57Z")

</div>

Logstash conf:

```auto
input {
  udp {
    host => "192.168.138.140"
    port => 5145
  }
}

filter {}

output {
  stdout {}
}

```

i forgot to mention that i have also another virtual machine that goes through logstash to kibana. It uses different logstash conf and haves input { beat etc

---

<div class="post-metadata">

**Author:** ![dadafaf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadafaf/32/131317_2.png) [@dadafaf](https://discuss.elastic.co/u/dadafaf)\
**Post date:** [February 1, 2024, 10:36am UTC](https://discuss.elastic.co/t/fortigate-30e-not-sending-any-logs-to-ubuntu-logstash/352270/4 "2024-02-01T10:36:18Z")

</div>

Oops i forgot to replace port 5145 to 5144 in that message. Thats not causing the problem

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 1, 2024, 10:39am UTC](https://discuss.elastic.co/t/fortigate-30e-not-sending-any-logs-to-ubuntu-logstash/352270/5 "2024-02-01T10:39:51Z")

</div>

Yeah, as mentioned, there is not much else to do on Logstash side.

Is logstash running without any issue? Can you see that it is listening on the port using a `netstat`?

If Logstash is running and listening on the port, then you need to troubleshoot your network.

---

<div class="post-metadata">

**Author:** ![dadafaf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadafaf/32/131317_2.png) [@dadafaf](https://discuss.elastic.co/u/dadafaf)\
**Post date:** [February 1, 2024, 10:47am UTC](https://discuss.elastic.co/t/fortigate-30e-not-sending-any-logs-to-ubuntu-logstash/352270/6 "2024-02-01T10:47:40Z")

</div>

root@ubuntulokipalvelin2:/etc# netstat -an | grep 5144  
udp 0 0 192.168.138.140:5144 0.0.0.0:\*

Do i need to make changes in rsyslog.conf file or do i need rsyslog at all. I used execute ping 192.168.138.140(logserver ip) in fortigate CLI-console and it has 100% packet loss.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 1, 2024, 10:52am UTC](https://discuss.elastic.co/t/fortigate-30e-not-sending-any-logs-to-ubuntu-logstash/352270/7 "2024-02-01T10:52:45Z")

</div>

> [@dadafaf](#):
>
> Do i need to make changes in rsyslog.conf file or do i need rsyslog at all.

There is no relation between Rsyslog and Logstash, if you want to send logs directly to Logstash you do not need Rsyslog.

> [@dadafaf](#):
>
> I used execute ping 192.168.138.140(logserver ip) in fortigate CLI-console and it has 100% packet loss.

This could mean basically two things:

- ICMP is blockec
- Your firewall cannot connect to the Logstash machine

Not sure if you have a telnet inthe fortigate console, but if you have try to telnet into the logstash server and port to see if it can connect to it.

This looks like a network issue, something is not correctly configured.

---

<div class="post-metadata">

**Author:** ![dadafaf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadafaf/32/131317_2.png) [@dadafaf](https://discuss.elastic.co/u/dadafaf)\
**Post date:** [February 1, 2024, 10:54am UTC](https://discuss.elastic.co/t/fortigate-30e-not-sending-any-logs-to-ubuntu-logstash/352270/8 "2024-02-01T10:54:48Z")

</div>

Ok. I also have NAT enabled in VMware, can this cause the problem? Do i have to use "Bridged".

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 1, 2024, 10:58am UTC](https://discuss.elastic.co/t/fortigate-30e-not-sending-any-logs-to-ubuntu-logstash/352270/9 "2024-02-01T10:58:24Z")

</div>

> [@dadafaf](#):
>
> I also have NAT enabled in VMware, can this cause the problem? Do i have to use "Bridged".

I'm not sure, you will need to troubleshoot it, Network issues aren't the scope of this forum.

I'm not able to help with network issues since I do not do much networking anymore, but I would recommend that you check every step to find what is missing.

---

<div class="post-metadata">

**Author:** ![dadafaf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadafaf/32/131317_2.png) [@dadafaf](https://discuss.elastic.co/u/dadafaf)\
**Post date:** [February 1, 2024, 10:59am UTC](https://discuss.elastic.co/t/fortigate-30e-not-sending-any-logs-to-ubuntu-logstash/352270/10 "2024-02-01T10:59:23Z")

</div>

Ok thanks for your time!

---

<div class="post-metadata">

**Author:** ![strawgate](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/strawgate/32/131008_2.png) [@strawgate](https://discuss.elastic.co/u/strawgate)\
**Post date:** [February 1, 2024, 1:09pm UTC](https://discuss.elastic.co/t/fortigate-30e-not-sending-any-logs-to-ubuntu-logstash/352270/12 "2024-02-01T13:09:27Z")

</div>

> [@dadafaf](#):
>
> have NAT enabled in VMware

You will need to enable port forwarding via the network editor (I think that's what it's called) otherwise the NAT translation will not forward the incoming packets to the VM. NAT allows many devices to share the same egress IP and so the port forwarding rule helps the NAT determine which inside host should receive the traffic.

Have you enabled port forwarding?

You may also find that, depending on the NAT implementation, and due to the NAT translation, that the source address on the messages is incorrect after translation.

---

<div class="post-metadata">

**Author:** ![dadafaf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadafaf/32/131317_2.png) [@dadafaf](https://discuss.elastic.co/u/dadafaf)\
**Post date:** [February 1, 2024, 1:24pm UTC](https://discuss.elastic.co/t/fortigate-30e-not-sending-any-logs-to-ubuntu-logstash/352270/13 "2024-02-01T13:24:34Z")

</div>

HI!

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/a/9a0cfa0aef28abf2848d92275091c536dccde475.png)  
Do you mean to add the fortigates ip address here? Can you specify.

---

<div class="post-metadata">

**Author:** ![strawgate](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/strawgate/32/131008_2.png) [@strawgate](https://discuss.elastic.co/u/strawgate)\
**Post date:** [February 1, 2024, 1:27pm UTC](https://discuss.elastic.co/t/fortigate-30e-not-sending-any-logs-to-ubuntu-logstash/352270/14 "2024-02-01T13:27:15Z")

</div>

Yes,

You need to add a port forward for a specific host port (5144) to get forwarded to your virtual machines NAT internal IP address which I think is 192.168.138.140

---

<div class="post-metadata">

**Author:** ![dadafaf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadafaf/32/131317_2.png) [@dadafaf](https://discuss.elastic.co/u/dadafaf)\
**Post date:** [February 1, 2024, 1:29pm UTC](https://discuss.elastic.co/t/fortigate-30e-not-sending-any-logs-to-ubuntu-logstash/352270/15 "2024-02-01T13:29:01Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/9/8/9853c526ae52d85cf1e8875d8dc8781ccc267216.png)  
Does this looks fine?

---

<div class="post-metadata">

**Author:** ![TimoHar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timohar/32/27257_2.png) [@TimoHar](https://discuss.elastic.co/u/TimoHar)\
**Post date:** [February 7, 2024, 7:49pm UTC](https://discuss.elastic.co/t/fortigate-30e-not-sending-any-logs-to-ubuntu-logstash/352270/16 "2024-02-07T19:49:14Z")

</div>

Have you considered using the Fortinet module for filebeat? Specifically, the firewall fileset? Check it out [here](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-fortinet.html)

No need to parse the syslogs yourself, the module handles all of that, and you have ECS-compliant logs in Elastic.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 6, 2024, 7:49pm UTC](https://discuss.elastic.co/t/fortigate-30e-not-sending-any-logs-to-ubuntu-logstash/352270/17 "2024-03-06T19:49:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
