FortiSIEM Discussions
Taher11
New Contributor III

Device can't be automatically added to CMDB

Hello team,

I have successfully configured our main L3 switches to send Syslog to our centralized Fortisiem log server, but with all of that done nothing was discovered by the CMDB.

Bellow the conf in the Cisco switch, the 64.55 is the IP address for the fortisiem.

Screenshot 2024-02-13 075047.png

EL MOUSTAPHA MOHAMED LEMINE TAHER
EL MOUSTAPHA MOHAMED LEMINE TAHER
3 REPLIES 3
adem_netsys
Contributor

Hi @Taher11 

 

Actually, when you send syslog to SIEM, you don't have to do discovery. it should automatically add it. I suggest you open tcpdump, you can check if the log is coming to SIEM

Taher11
New Contributor III

Exactly @adem_netsys , but nothing was seen as syslog from that particular switch when running tcpdump on the fortisiem.

 

Screenshot 2024-02-13 080220.png

EL MOUSTAPHA MOHAMED LEMINE TAHER
EL MOUSTAPHA MOHAMED LEMINE TAHER
adem_netsys

In this case, we can say that syslog is not going to SIEM. If there is an FW in between, you need to check the permissions there.