Skip to main content
saharawolf
New Member
June 12, 2014
Question

Log analysis with ManageEngine firewall analyzer !

  • June 12, 2014
  • 4 replies
  • 9307 views
Hello everyone, I used to have a fortianalyzer 800B to log and make reports for my fortigates. However, my 800B doesn' t support V5 firmware and thus it doesn' t analyze logs from upgraded firewalls. I' ve been looking for a workaround to get my logs analyzed and found the ManageEngine firewall analyzer witch support Fortigates (that' s what they say). I configured everything and get my forti sending logs to the analyzer but i found that the reports aren' t like what i expected (not like fortianalyzer ones). For example, i found that manageengine classes teamviewer or MS update or anything blocked as an attack !! that' s weird ! Have any one tried using manageengine ? Or can you tell me a suitable software to do this task like the fortianalyzer ? Thanks to everyone who would help. Regards

    4 replies

    billp
    New Member
    June 12, 2014
    I assume you' ve looked at FortiCloud? That might be the least expensive solution if it works for you. If you have some facility with setting up a syslog server, I' ve found that Logstash can do a nice job of parsing the existing Fortigate logs. This is really a DIY approach to interpret logs, though, and not an out-of-the-box solution. It doesn' t generate reports as much as it allows you to create specific views into firewall activity. Still -- it has all the data from your logs. I' ve heard good things about the free Cyberoam Iview software, but have not used it. That' s probably similar to ManageEngine. Logmojo.com looks like a good non-free solution and is tailored for Fortigate. Hope that helps. I' m a big fan of Logstash, but it' s not for everyone.
    Nihas
    New Member
    July 18, 2014
    Hi , You can try Cyber Roam Iview http://www.cyberoam-iview.org/
    FortiAdam
    New Member
    July 29, 2014
    I used ManageEngine for a short period of time and noticed the same issues. All of the denied UDP traffic that my firewalls were logging as locally denied was showing as " attack" traffic. You might consider LogMojo by Security Confidence as well. It' s a cloud based log analysis tool that you pay for based on the amount of storage you need.
    Mark_Oakton
    New Member
    October 15, 2014
    logmojo works well on fortigate traffic
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!