FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
psalian
Staff
Staff
Article Id 192587

Description

 

This article describes the steps to add a third party device to FortiAnalyzer where FortiAnalyzer is the syslog server.

 

Scope

 

FortiAnalyzer.

Solution

 

It is not possible to add a third party device directly from FortiAnalyzer into the syslog ADOM.

This is due to the way the serial number is stored under the syslog ADOM. If the device is added from FortiAnalyzer, FortiAnalyzer would not recognize the serial number and would provide the following error:

 

The device's serial number does not match database

 

Steps to add the device to FortiAnalyzer:

 

  1. On the Third party device, add FortiAnalyzer as a syslog server. Configure it to send logs to FortiAnalyzer.
  2. On FortiAnalyzer, the device will show up under unregistered devices. Right-click on it, promote it, and add it under Syslog ADOM.
  3. Enter Syslog ADOM to see the device added in there.

 

Related articles: