Skip to main content
New Member
July 13, 2026
Question

Integrated Darktrace Syslog with FortiAnalyzer.

  • July 13, 2026
  • 1 reply
  • 37 views

I have integrated Darktrace Syslog with FortiAnalyzer. When Darktrace sends logs in JSON format, the log messages are truncated in FortiAnalyzer. However, when I configure Darktrace to send logs in CEF format, the Message field in FortiAnalyzer is empty.

Could you please advise on the cause of this behavior and recommend the appropriate configuration to ensure the complete log message is displayed in FortiAnalyzer?

1 reply

AEK
SuperUser
SuperUser
July 13, 2026

I didn’t do that before but I guess you need to do some custom log parsing.

https://docs.fortinet.com/document/fortianalyzer/7.6.0/custom-log-parsers/88208/introduction

Hope it helps.

AEK
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!