Created on 11-04-2024 05:46 AM Edited on 11-04-2024 05:47 AM
Description |
This article describes how to configure SIEM event streaming from the Reveal platforms to Microsoft Sentinel. |
Scope | FortiDLP. |
Solution |
Prerequisites
Setup overview. Deploy custom Template: Initially, it is necessary to deploy the data connector. More details can be found On Microsoft's page. However, the easiest way to do this is to use the Deploy Custom Template option within Azure. Below are the steps to add the template:
The Custom Data Connector should be created at this point and will redirect to the Templates Overview page. It is possible to continue setting up the resource from here in the next section.
Creating a SIEM Stream in Reveal: Create a SIEM stream within the Reveal Console. The steps are described in the deployment guide however in short the steps are below:
The access token will only be shown at this time. If there are issues with the Access Token after this point, re-generate the Token for use later and the previous token will no longer be valid.
Configuring the Data Connector in Sentinel: At this stage, a Data Connector was created and a Reveal SIEM Stream was set up. Now, tie the two together. The steps below will perform this task.
At this point, the stream should be connected and events should be received on the new Sentinel Data Connector. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.