Skip to main content
IsuruTharanga
Visitor III
November 24, 2021
Question

FortiSIEM - AWS Organizations

  • November 24, 2021
  • 1 reply
  • 1027 views
Hi,

I would like to get a clarification for the following,

In an AWS Environment which uses "AWS Organizations" to segregate the CI/CD pipeline (ex: dev, test, prod), do we have to deploy separate FortiSIEM collectors on each account or is it possible to collect logs through 1 collector node?

------------------------------
Cheers,
Isuru
------------------------------

    1 reply

    kcanalichio
    New Member
    November 26, 2021

    As long as the collector has access to all three networks, you can have one collector. Really depends on your network security model.



    -------------------------------------------
    Original Message:
    Sent: 11/24/2021 5:08:00 AM
    From: Isuru
    Subject: FortiSIEM - AWS Organizations

    Hi,

    I would like to get a clarification for the following,

    In an AWS Environment which uses "AWS Organizations" to segregate the CI/CD pipeline (ex: dev, test, prod), do we have to deploy separate FortiSIEM collectors on each account or is it possible to collect logs through 1 collector node?

    ------------------------------
    Cheers,
    Isuru
    ------------------------------
    IsuruTharanga
    Visitor III
    November 26, 2021
    Hi Kevin,

    Thanks for the insight !!

    ------------------------------
    Cheers,
    Isuru
    ------------------------------
    -------------------------------------------
    Original Message:
    Sent: Nov 26, 2021 08:12 AM
    From: Kevin Canalichio
    Subject: FortiSIEM - AWS Organizations

    As long as the collector has access to all three networks, you can have one collector. Really depends on your network security model.




    Original Message:
    Sent: 11/24/2021 5:08:00 AM
    From: Isuru
    Subject: FortiSIEM - AWS Organizations

    Hi,

    I would like to get a clarification for the following,

    In an AWS Environment which uses "AWS Organizations" to segregate the CI/CD pipeline (ex: dev, test, prod), do we have to deploy separate FortiSIEM collectors on each account or is it possible to collect logs through 1 collector node?

    ------------------------------
    Cheers,
    Isuru
    ------------------------------