Skip to main content
albaker1
New Member
April 20, 2023
Solved

How to configure syslog to use "Threat Weight" on FortiManager

  • April 20, 2023
  • 2 replies
  • 1479 views

Our FTM is running 7.2.2 and our FTG's are running 7.2.4. These are relatively new installations, and we're trying to trim the amount of syslog traffic to our SIEM. On the FTM at Device Manager > [FortiGate] > Log & Report > Threat Weight, there are several security settings. I don't see where to apply these to the syslog settings, nor can I find any documentation to do so. The "Log Threat Weight" is enabled. We do not have FortiAnalyzer. Is there a way to configure syslog to send security-related info that can be ingested into our SIEM without having a bunch of extra fluff? Thanks

Best answer by gfleming

I don't believe Threat Weight is what you want here.

 

What you want is to filter your FortiGate logs that are being sent to your SIEM.

 

https://docs.fortinet.com/document/fortigate/7.2.4/administration-guide/250999/log-settings-and-targets

2 replies

gfleming
Staff
gflemingAnswer
Staff
April 20, 2023

I don't believe Threat Weight is what you want here.

 

What you want is to filter your FortiGate logs that are being sent to your SIEM.

 

https://docs.fortinet.com/document/fortigate/7.2.4/administration-guide/250999/log-settings-and-targets

albaker1
albaker1Author
New Member
April 21, 2023

OK. That's what we are doing right now. I think on a previous version of code, I saw something with SIEM in the logging configuration. Could be mistaken. Thanks for your input.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!