Log Source SIEM
Hi guys,
In fortisiem, some of the log sources are sent to supervisor and some to collector. Is there any way to see this on the GUI other than getting a dump?
Hi guys,
In fortisiem, some of the log sources are sent to supervisor and some to collector. Is there any way to see this on the GUI other than getting a dump?
Hi
I'm thinking that you could achieve it with an analytics search. I don't actually have a collector in my test setup, but my idea is to search all logs and then aggregate the search with reporting IP and collector name or collector id. Then use the count function as per the screenshot. I'm not sure if it will work if you have loads of events, but maybe you could play around with the filters to help narrow down the search.
I hope it helps!
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.