I've FortiSASE and FortiSIEM but I don't have FortiAnalyzer.
In FortiSASE support syslog,cvf format, I'm try send to FortiSIEM with result connected.
But I don't know how show log on the FortiSIEM analytic, report, ... .
Please advise.
#FortiSIEM
Hi @opastera ,
Yes you can enter SIEM IP Address in FortiSASE syslog server destination . No additional configuration required.
Basic level logs would be parsed, for any advance logging you would have to write a custom parser.
Hi @opastera,
Note two things there:
In case of a collector, you probably need to check "SPA" since you will send the syslog through the internet otherwise.
FortiSASE logs will come in with the reporting ip of the current POP, which will frequently change (especially if it's the dynamic one of the SD-WAN/BGP config). If your license is on number of devices, make sure you're always up to date where the logs are coming from.
Best,
Christian
Welcome to your new Fortinet Community!
You'll find your previous forum posts under "Forums"
User | Count |
---|---|
72 | |
25 | |
15 | |
10 | |
10 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.