Created on
06-13-2025
05:16 AM
Edited on
10-29-2025
05:15 AM
By
Stephen_G
| Description | This article describes pre-requisites needed for the log parser feature to be visible. |
| Scope | FortiAnalyzer. |
| Solution |
This article talks about the steps to check on FortiAnalyzer in case Log parser TAB is not seen under Incidents & Events -> Log Parsers.
More about this feature is covered in Siem-log-parsers - FortiAnalyzer 7.6.3 administration guide.
Things to confirm on the device:
unset disable-module <----- To enable all the modules in FortiAnalyzer. get <----- This command lists the current config to check if any other modules other than SIEM are disabled as per the customer requirement. set disable-module soc ot-view <----- This command removes SIEM from the list of disabled modules, keeping the other modules disabled and enabling only SIEM. end
Once these three conditions are met, the log parser tab will be visible.
Note: Content Packet versions can be seen from Incidents & Events -> FortiGuard Services -> SOC Automation. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.