Cybersecurity Forum

This forum is for all security enthusiasts to discuss Fortinet's latest & evolving technologies and to connect & network with peers in the cybersecurity hemisphere. Share and learn on a broad range of topics like best practices, use cases, integrations and more. For support specific questions/resources, please visit the Support Forum or the Knowledge Base.

ManRod
New Contributor II

MAC to Vendor

Hi there,

is there any chance to show the mac vendor of a mac inside an event?

I can see there is a MACByVendor.csv, a MACByVendor.txt and a MACByVendorGroup.csv under /opt/phoenix/data-definition, but have no clue if or how to use it.

Wonder why this is not correlated by default, like i.e. GEO IP.

Regards
Manuel

2 REPLIES 2
FSM_FTNT
Staff
Staff

Hi Manuel,

I checked on this internally, this list is not used within FortiSIEM currently. I am looking into a workaround using parser customization and the code attribute lookups.

Thanks

Dan

------------------------------
Daniel
FortiSIEM Product Manager
------------------------------
ManRod
New Contributor II

Hi, 

Parser would be perfect. Want to use it for a customised DHCP Parser and see which Vendor gets DHCPNACK.

Regards
Manuel