FortiSIEM Discussions
opastera
New Contributor

Can send syslog from FortiSASE to FortiSIEM?

I've FortiSASE and FortiSIEM but I don't have FortiAnalyzer.

 

In FortiSASE support syslog,cvf format, I'm try send to FortiSIEM with result connected.

 

But I don't know how show log on the FortiSIEM analytic, report, ... .

 

Please advise.

 

#FortiSIEM 

2 REPLIES 2
premchanderr
Staff & Editor
Staff & Editor

Hi @opastera ,

 

Yes you can enter SIEM IP Address  in FortiSASE syslog server destination . No additional configuration required.

 

Basic level logs would be parsed, for any advance logging you would have to write a custom parser. 

Regards,
Prem Chander R
Secusaurus
Contributor III

Hi @opastera,

 

Note two things there:

In case of a collector, you probably need to check "SPA" since you will send the syslog through the internet otherwise.

FortiSASE logs will come in with the reporting ip of the current POP, which will frequently change (especially if it's the dynamic one of the SD-WAN/BGP config). If your license is on number of devices, make sure you're always up to date where the logs are coming from.

 

Best,

Christian

FCX #003451 | Fortinet Advanced Partner
FCX #003451 | Fortinet Advanced Partner