Skip to main content
alled
New Member
April 9, 2024
Question

Parse syslogs of different devices in FortiAnalyzer

  • April 9, 2024
  • 3 replies
  • 2892 views

Hi guys,

is it possible with the FortiAnalyzer to parse information out of a syslog, for example from a Sophos XG Firewall? Is there a site where i can find already written Log parsers? Or how do i write one?
We want to ingest Logs from different sources, Sophos, Juniper, Checkpoint, Palo Alto,... via syslog in FAZ and parse them, to run Event Handlers on those parsed logs. Is that even possible with FAZ?

Thanks for your answers :)

3 replies

ozkanaltas
Valued Contributor III
April 9, 2024

Hello @alled ,

 

FortiAnalyzer can only collect logs from Fortinet products. If you want to collect and parse logs from other devices, you can use an SIEM solution such as FortiSIEM. 

 

 

seguridadinformatica
New Member
April 23, 2024

Yes, You can add third party devices via syslog, the bad news is that you need to configure a JSON parser adhoc to ingest third party devices and match every field of the log.
There is little information for build a JSON parser for FAZ.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!