Automatically hashing logs in FortiAnalyzer (5651)
From FortiAnalyzer 4.2 patch 1 onwards, logs are automatically hashed. Steps to set this up in Analyzer:
1. Set pool.ntp.org (or another) as the time server so it gets the NTP time stamp.
2. In the Analyzer console type “config system global”, then set log-checksum md5, and type end.
Now incoming logs are hashed and timestamped.
To export these logs for backup:
In Log options, configure “send 100 MB log to this FTP server”. We recommend this because even if the analyzer disk fails, you can import the logs onto a new disk.
Some screenshots about the interface are attached.

With this free software you can time-stamp your logs. No separate log solution is required.
Note: if DHCP is used, the DHCP server logs should also be sent to the same FTP server to be hashed.
uMMAN




