Skip to main content
karim1
New Member
November 6, 2024
Question

Configuring FortiEMS to Forward Additional Syslogs Logs to Wazuh SIEM

  • November 6, 2024
  • 1 reply
  • 4188 views

Hello everyone,
I am currently configuring a SIEM solution (Wazuh) and have successfully set up log forwarding from FortiEMS via syslog. However,  the logs I am currently receiving on the SIEM are as follows:

  • Status change of FortiClient to online
  • FortiClient status marked as offline by EMS
  • FortiClient IP address changes

I would like to capture additional logs, such as those generated by the vulnerability scanner, antivirus, web filter, and other security features. Could you advise on how to configure FortiEMS to send these additional logs to Wazuh?

1 reply

ebilcari
Staff
Staff
November 6, 2024

You may need a FortiAnalyzer to collect the logs from the FortiClients first than forward them to the 3rd party SIEM. The steps are also shown in this article.

Emirjon
karim1
karim1Author
New Member
November 6, 2024

Thank you for your response @ebilcari.
However, Is there a way I can use syslog to send logs directly to the SIEM without going through a FortiAnalyzer since we don't own this solution.