FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
mmishra_FTNT
Staff
Staff
Article Id 396198
Description This article describes pre-requisites needed for the log parser feature to be visible.
Scope FortiAnalyzer.
Solution

This article talks about the steps to check on FortiAnalyzer in case Log parser TAB is not seen under Incidents & Events -> Log Parsers.

 

More about this feature is covered in Siem-log-parsers - FortiAnalyzer 7.6.3 administration guide.

 

Things to confirm on the device:

 

  1. Security Automation Service license.

License.PNG

 

  1. ADOM should be a Fabric ADOM.

Fabric.PNG

 

  1. The SIEM module should be enabled:

config system global
    unset disable-module
end

 

Once these three conditions are met, the log parser tab should be visible.

 

Note: Content Packet versions can be seen from Incidents & Events -> FortiGuard Services -> SOC Automation.

 

SOC.PNG