FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
heng
Staff
Staff
Article Id 274125
Description

 

This article describes how to enable Syslog logging by using protocol: UDP in FortiSOAR to send log to FortiAnalyzer.

 

Scope

 

FortiSOAR, FortiAnalyzer

 

Solution

 

  1. Login into FortiSOAR GUI, select the small little Settings icon on the top-right corner. 

 

image.png

 

  1.  Navigate to System -> System Configuration -> Log Forwarding. It is possible to configure all the FortiAnalyzer mandatory configuration data, such as IP address, protocol, port number, and log type to be forwarded (Audit Logs, Application Logs). Audit Logs level can be set to Basic or Detailed, and it is possible to define an Audit Log forwarding rule to match a specific condition -> Save.

 

image.png

 

  1.  Login into FortiAnalyzer to authorize the FortiSOAR to join the logging request, wait a couple of minutes for the device request to appear in the Device Manager and then authorize it into an ADOM.

 

image.png

 

image.png

 

  1. In the FortiAnalyzer again, navigate to Log View -> FortiSOAR, and it will be possible to view the ingested event log from the FortiSOAR.

 

image.png

Contributors