Skip to main content
Soulaima
Visitor III
May 27, 2025
Question

Fortiweb logs to FortiSiem

  • May 27, 2025
  • 2 replies
  • 1505 views

Hi 

i wanna configure Fortiweb to log to my FortiSiem. can someone guide me through 

    2 replies

    Secusaurus
    Contributor III
    May 27, 2025
    NSE8 | Fortinet Advanced MSSP Partner
    Soulaima
    SoulaimaAuthor
    Visitor III
    May 28, 2025

    Hi @Secusaurus,

    I’ve already followed the documentation, but it’s not very detailed. Here’s what I’ve done so far, but I still can’t see FortiWeb in FortiSIEM.
    Do you have any suggestions on what I should change or add?

    Thanks in advance!my collector's ip 10.6.5.11my collector's ip 10.6.5.11

    7.png8.png

    adriatikb
    Visitor III
    May 28, 2025

    Hi,

    Try to ping the collector from fortiweb.

    Check with tcpdump in the collector if you receive syslog packets from the FortiWeb IP.

    AB

    Soulaima
    SoulaimaAuthor
    Visitor III
    May 28, 2025
     
     

    10.pngI can ping from FortiWeb to the collector, but not the other way around. Could this be the problem?dicoverydicovery

     

    Secusaurus
    Contributor III
    May 28, 2025

    Hi @Soulaima,

     

    Concerning syslog, this should not be an issue. You should receive logs from the FortiWeb on the collector. Next step would be tcdump (packet capture) on the collector for the udp packages.

     

    Concerning the discovery process: You can either discover without ping (set the option) or enable ping on the interface of the FortiWeb (probably it's just disabled there).

     

    Best,

    Christian

    NSE8 | Fortinet Advanced MSSP Partner