- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
join events from two log sources together in search
- Labels:
-
SIEM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Sadek,
In version 6.4.0 released a lookup table feature has been added that allows you to 1) Populate a table 2) use it for analytic filters and lookups
https://docs.fortinet.com/document/fortisiem/6.4.0/release-notes/456886/whats-new-in-6-4-0#Lookup
Here is an example of its use:
1) Create a lookup table with SourceIP and User as the values. Make the SourceIP field the key.
2) Populate the table using a scheduled report - report on the clearpass logs with user and IP mapped to the lookup table values. It should look like this
3) Add a filter as needed to Analytics. In this example we are saying, "Only show logs where the Source IP is in the Lookup Table AND the User in the Lookup Table is not 'N/A'"
4) The we use the Display Fields to Looup the Source IP and display the User
Let us know how you get on.
Thanks
------------------------------
Daniel
FortiSIEM Product Manager
------------------------------
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Use the concept of lookup table in 6.4.0.
Store clear path for authentication in a lookup table with IP as key.
*** Please note that this message and any attachments may contain confidential and proprietary material and information and are intended only for the use of the intended recipient(s). If you are not the intended recipient, you are hereby notified that any review, use, disclosure, dissemination, distribution or copying of this message and any attachments is strictly prohibited. If you have received this email in error, please immediately notify the sender and destroy this e-mail and any attachments and all copies, whether electronic or printed. Please also note that any views, opinions, conclusions or commitments expressed in this message are those of the individual sender and do not necessarily reflect the views of Fortinet, Inc., its affiliates, and emails are not binding on Fortinet and only a writing manually signed by Fortinet's General Counsel can be a binding commitment of Fortinet to Fortinet's customers or partners. Thank you. ***
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We have posted a more in-depth blog post on this topic
https://fusecommunity.fortinet.com/blogs/dusan/2022/02/14/fortisiem-lookup-tables-64
Thanks
Dan
------------------------------
Daniel
FortiSIEM Product Manager
------------------------------
