Skip to main content
Waloo5
Explorer III
March 22, 2024
Question

FortSIEM and Firewall FortiGate and FortiAnalyser

  • March 22, 2024
  • 2 replies
  • 1286 views

Hi all,

I want to know the best practice of implementing firewalls logs in FortiSIEM.

I have 10 Firewalls Fortigates and all are loged in FortiAnalyser and my question is I configure syslog 

2 replies

AEK
SuperUser
SuperUser
March 22, 2024

Hi Waloo

Regarding which logs you send, just send all logs to FortiSIEM, I mean UTM logs, all traffic logs, event logs, ... all, don't leave anything.

Regarding integration, check this for more details.

https://docs.fortinet.com/document/fortisiem/7.1.4/external-systems-configuration-guide/751381/fortinet-fortigate-firewall

On the other hand you can also configure log forwarding from FAZ to FSM if you don't want to send to both from FGT.

https://community.fortinet.com/t5/FortiAnalyzer/Technical-Tip-Integrate-FortiAnalyzer-and-FortiSIEM/ta-p/220756

AEK
Waloo5
Waloo5Author
Explorer III
March 22, 2024

Thx AEK for your repli.

My question is to Know the Best practice of intégration in fortiSIEM, to have logs from all firewalls FGT or only from FortiAnalyser.

And second question if I intégred only FortiAnalyser it's deduce only one licence or nombres of all firewalls ?

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!