Description | This article describes the steps to configure the IBM Qradar as the Syslog server of the FortiGate. |
Scope | FortiGate, IBM Qradar. |
Solution |
To set up IBM QRadar as the Syslog server for FortiGate to send its logs to, follow the steps:
Step 1: Configure IBM QRadar to Receive Syslog Messages.
Select 'New Log Source'.
Select 'Single Log Source'.
Search for the FortiGate.
Choose the 'Syslog' protocol.
Here, it is necessary to fill out these boxes: Name: Give it a name, like 'FortiGate Syslog'. Enabled: This is to enable/disable the log source. Groups: If having groups of log sources pre-configured it is possible to choose them. Events Coalescing: Enable or disable it depending on how it is desired to handle duplicate events.
Log Source Identifier: Type the IP address of the FortiGate device. Select Save.
If the Source is showing as 'Not Available' is required to 'deploy' the changes.
Step 2: Configure FortiGate to Send Syslog to QRadar. Log in to the FortiGate device via a CLI or GUI.
config log syslogd setting
config log syslogd filter
Log in to the FortiGate GUI.
Input the IP address of the QRadar server. Select Apply.
Related article: Troubleshooting Tip: Syslog and log trouble shooting via CLI |
Excellent article @Cayazo !! Keep up the great job!!!
Excellent contribution @Cayazo
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.