FortiSIEM Discussions
Taher11
New Contributor III

Firepowe management center integration with fortisiem

Hello, 

I successfully integrated the FMC from Cisco with the fortisiem platform, but all the logs I received are unkown.

Any suggestion to resolve this issue?

Screenshot 2023-08-25 075339.png

EL MOUSTAPHA MOHAMED LEMINE TAHER
EL MOUSTAPHA MOHAMED LEMINE TAHER
1 Solution
FSM_FTNT
Staff
Staff

Hi, have a look at the attached parser.

 

You will need to create a new parser https://help.fortinet.com/fsiem/7-0-1/Online-Help/HTML5_Help/Creating-a-Custom-Parser.html

 

If you can provide more sample events, we can improve this parser.

 

Thanks

View solution in original post

5 REPLIES 5
FSM_FTNT
Staff
Staff

Hi,

 

Can you provide some more sample events? You can send the to me directly and we will check.

 

Are these events generated by FTD and forwarded via FMC or are they FMC generated events?

 

Thanks

Taher11
New Contributor III

The events are generated by the FMC :

 

Screenshot 2023-08-31 092723.png

 

EL MOUSTAPHA MOHAMED LEMINE TAHER
EL MOUSTAPHA MOHAMED LEMINE TAHER
FSM_FTNT
Staff
Staff

We need the raw log, can you export in CSV and share or post direct to me?

FSM_FTNT
Staff
Staff

Hi, have a look at the attached parser.

 

You will need to create a new parser https://help.fortinet.com/fsiem/7-0-1/Online-Help/HTML5_Help/Creating-a-Custom-Parser.html

 

If you can provide more sample events, we can improve this parser.

 

Thanks

Taher11
New Contributor III

Thank you for your support

EL MOUSTAPHA MOHAMED LEMINE TAHER
EL MOUSTAPHA MOHAMED LEMINE TAHER