FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
mmishra_FTNT
Staff
Staff
Article Id 396198
Description This article describes pre-requisites needed for the log parser feature to be visible.
Scope FortiAnalyzer.
Solution

This article talks about the steps to check on FortiAnalyzer in case Log parser TAB is not seen under Incidents & Events -> Log Parsers.

 

More about this feature is covered in Siem-log-parsers - FortiAnalyzer 7.6.3 administration guide.

 

Things to confirm on the device:

 

  1. Security Automation Service license.

License.PNG

 

  1. ADOM should be a Fabric ADOM.

Fabric.PNG

 

  1. The SIEM module should be enabled:


config system global

unset disable-module <----- To enable all the modules in FortiAnalyzer.

get <----- This command lists the current config to check if any other modules other than SIEM are disabled as per the customer requirement.

set disable-module soc ot-view <----- This command removes SIEM from the list of disabled modules, keeping the other modules disabled and enabling only SIEM.

end

 

Once these three conditions are met, the log parser tab will be visible.

 

Note: Content Packet versions can be seen from Incidents & Events -> FortiGuard Services -> SOC Automation.

 

SOC.PNG