Watch every request hit your FortiGate, in real time, in 3D. Vigil is a free, open-source, self-hosted FortiGate syslog dashboard: live attack visualisation, inbound rule risk grading, live configuration-change tracking and plain-English investigations. It is one Docker container, and the integration is one CLI block on the firewall.
Get it on GitHub → · Read the blog post · FortiAnalyzer alternative? · FortiGate setup · Install guide

git clone https://github.com/vigiltech01/vigil.git && cd vigil && ./install.sh
Already sending the FortiGate to this machine’s own syslog server on port 514? The installer detects it and Vigil reads that log file read-only - no change on the firewall.
Needs Docker with the Compose v2 plugin. On a fresh machine run curl -fsSL https://get.docker.com | sudo sh first
(or on Ubuntu: sudo apt install -y docker.io docker-compose-v2) - see Install Docker.
Open http://<host>:8080, create the admin account and paste the syslog settings into the FortiGate CLI:
config log syslogd setting
set status enable
set server "<vigil-machine-ip>"
set port 514
set format default
end
No agent, no API user or token, no firewall password, no FortiAnalyzer, no cloud account. Vigil only listens for syslog.


Vigil is built by a small startup building the best open-source security and SIEM tools. Investors and crowdfunding backers are welcome: contact us or sponsor us on GitHub.
Apache 2.0 licensed. FortiGate, FortiOS, FortiAnalyzer and Fortinet are trademarks of Fortinet, Inc. Vigil is an independent project and is not affiliated with or endorsed by Fortinet.