Cybersecurity Forum

This forum is for all security enthusiasts to discuss Fortinet's latest & evolving technologies and to connect & network with peers in the cybersecurity hemisphere. Share and learn on a broad range of topics like best practices, use cases, integrations and more. For support specific questions/resources, please visit the Support Forum or the Knowledge Base.

KalanaChandrasiri
New Contributor

FortiWeb

Hi People,

I need to configure FortiWeb syslogs to FortiWeb.

In Fortiweb 4000 it has both Syslog Policy and SIEM policy (Under Log Policy). What is the supportive method for FortiSIEM?

If we configured SIEM policy it shows only QRadar LEEF and ArcSight CEF. What is best method.

I saw that there is a comment as "CEF" is not support with FortiSIEM.


Regards,
Kalana

------------------------------
kalana
------------------------------
1 Solution
FSM_FTNT
Staff
Staff

Hi Kalana,

FortiSIEM version 5.2.5 supports FortiWeb using Syslog format.

The recevied log format should be key value pair format, similar to this:

date=2016-02-18 time=10:00:05 log_id=00001002 msg_id=000067508821 device_id=FV400D3A15450010 vd="root" timezone="(GMT+3:00)Baghdad" type=event subtype="admin" pri=information trigger_policy="" user=admin ui=GUI action=edit status=success msg="User admin changed global from GUI(196.168.6.66)"

View solution in original post

3 REPLIES 3
FSM_FTNT
Staff
Staff

Hi Kalana,

FortiSIEM version 5.2.5 supports FortiWeb using Syslog format.

The recevied log format should be key value pair format, similar to this:

date=2016-02-18 time=10:00:05 log_id=00001002 msg_id=000067508821 device_id=FV400D3A15450010 vd="root" timezone="(GMT+3:00)Baghdad" type=event subtype="admin" pri=information trigger_policy="" user=admin ui=GUI action=edit status=success msg="User admin changed global from GUI(196.168.6.66)"
KalanaChandrasiri

@Daniel,

Are we able to configure custom log format in FortiWeb ?
FSM_FTNT

The format needs to be the standard Key Value Pair log format. If you customise then the FortiSIEM parser may also need to be customised.