Which FortiGate in a Security Fabric sends logs to FortiAnalyzer?
Select an option, then click Submit answer.
Reference / correct answer:
Each FortiGate in the Security Fabric.
Most accepted answer: B. Each FortiGate in the Security Fabric.
Community votes: B=6, C=2
Selected Answer: B In a Security Fabric, every FortiGate device sends its logs directly to FortiAnalyzer, independently of the root FortiGate. While the root FortiGate is typically responsible for configuring and managing the log forwarding configuration, all leaf FortiGates (downstream devices) send their logs to FortiAnalyzer, ensuring complete visibility across the Security Fabric. This design ensures redundancy and guarantees that logs are not lost if a specific FortiGate device in the fabric fails. Other options are incorrect for the following reasons: A: Only the root FortiGate is responsible for configuration synchronization, not exclusive logging. C: NAT or UTM devices log traffic details, but all devices in the Security Fabric send logs, not just these. D: Logging is not limited to the last FortiGate in the session chain; all devices log their activity independently. upvoted 1 times
Selected Answer: B All Fortigates send logs to FortiAnalyzer. But session logs only sent by first fortigate that handle the session, so it's not being duplicated. If any fortigate that performs NAT or UTM, it will generate additional log for that session and send it to FortiAnalyzer. See page 69 upvoted 1 times
Selected Answer: B Study Guide 7.2 Page 68 - see the last comment. upvoted 2 times
Selected Answer: C C is correct. see on P.68. Doesn't create duplicate except NAT and UTM traffic upvoted 1 times
Selected Answer: C Study guide P.69 upvoted 1 times