Hi Guys,
I am new to fortisiem, i have question, currently our Fortisiem monitor Cisco ASA firewall, but as for now it did not flag any rules from Fortisiem.
It is i have to manually create rules for any security incident for Cisco ASA? If anyone could share rules for ASA or any use case that you guys used.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi Guys,
I am new to fortisiem, i have question, currently our Fortisiem monitor Cisco ASA firewall, but as for now it did not flag any rules from Fortisiem.
It is i have to manually create rules for any security incident for Cisco ASA? If anyone could share rules for ASA or any use case that you guys used.
Hi Daniel,
Thanks suggestion given, after going through i found out i need to activate some of the rules, maybe someone before me deactivated it.
-------------------------------------------Hi Guys,
I am new to fortisiem, i have question, currently our Fortisiem monitor Cisco ASA firewall, but as for now it did not flag any rules from Fortisiem.
It is i have to manually create rules for any security incident for Cisco ASA? If anyone could share rules for ASA or any use case that you guys used.
IF | System Event Category = 2 AND Event Type IN PH_AUDIT_OBJECT_CREATED, PH_AUDIT_OBJECT_DELETED, PH_AUDIT_OBJECT_UPDATED AND OS Object Type = Rule |
WHERE | COUNT(Matched Events) >= 1 |
GROUPBY | User,Object Name,Organization Name |
Hi Daniel,
Thanks suggestion given, after going through i found out i need to activate some of the rules, maybe someone before me deactivated it.
Hi Guys,
I am new to fortisiem, i have question, currently our Fortisiem monitor Cisco ASA firewall, but as for now it did not flag any rules from Fortisiem.
It is i have to manually create rules for any security incident for Cisco ASA? If anyone could share rules for ASA or any use case that you guys used.
Welcome to your new Fortinet Community!
You'll find your previous forum posts under "Forums"
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.