Understanding FortiNDR Log Metadata and All Log Types for SIEM Integration
I would like to better understand the FortiNDR logs and all of their metadata because I’m planning to integrate the logs into a SIEM.
I’ve reviewed the official Fortinet documentation, but it only includes a few samples. I’m looking for a more comprehensive guide that explains every log field, all possible metadata attributes, all log types, and attack/malware/AV event examples : basically all types of logs that could be sent to a SIEM, along with detailed explanations of each field and what it means.
If there is any reference, whitepaper, or guide that thoroughly explains the FortiNDR log structure and samples (including detection logs, malware logs, AV logs, etc.) in detail, it would really help me understand each type and how to parse them properly.
Thank you in advance !!!