Description | This article describes the challenges of integrating a FortiGate into an IBM Q-RADAR SIEM solution. |
Scope | FortiGate. |
Solution |
The integration of FortiGate or Forti Analyzer to the IBM SIEM solution might not work as expected. The configuration is similar to the Syslog server configuration on FortiGate:
Under 'Log Settings', enable the syslog option and mention the FQDN or IP address of the SIEM collector. SIEM collector is an application installed on the VM that will fetch the details about the device.
Make sure to forward all the event logs so an SIEM collector and manage and send alerts/notifications to the Admin.
The common challenges are described below:
Apart from the above issues, the troubleshooting is the same as syslog settings.
Related articles: Troubleshooting Tip: Syslog and log trouble shooting via CLITechnical Tip: FortiGate and syslog communication check |