FortiSIEM Discussions
Taher11
New Contributor III

Forcepoint NGFW Integration with Fortisiem

I succeeded to forward logs from the forcepoint NGFW to fortiSiem but all the event types received are unknown " unknown event type".

 

FortiSIEM , #Forcepoint

 

   

EL MOUSTAPHA MOHAMED LEMINE TAHER
EL MOUSTAPHA MOHAMED LEMINE TAHER
1 Solution
Taher11
New Contributor III

Hello we have developed a new parser and the problem was resolved, thank you for your time 

EL MOUSTAPHA MOHAMED LEMINE TAHER

View solution in original post

EL MOUSTAPHA MOHAMED LEMINE TAHER
6 REPLIES 6
FSM_FTNT
Staff
Staff

Are the events being sent in CEF format?

 

Can you share some sample events so that we can see what the issue is?

 

This is a sample event format that FortiSIEM expects to receive:

 

<6>CEF:0|FORCEPOINT|Alert|6.0.1|71257|TCP_Segment-SYN-No-Options|0|spt=2890 deviceExternalId=FW2 node 1 dmac=00:50:56:86:5E:16 dst=192.168.91.67 app=TCP/30152 rt=Sep 22 2016 23:38:00 deviceFacility=Packet filter act=Terminate deviceInboundInterface=2 proto=6 dpt=30152 src=192.168.155.35 dvc=192.168.94.51 dvchost=192.168.94.51 smac=00:10:DB:FF:10:01 cs1Label=RuleId cs1=97.0

Taher11
New Contributor III

We are using the LEEF format, but even if we change it to CEF the event type remains unkown.

 

<6>LEEF:1.0|Forcepoint|Firewall|7.0.2|Connection_Allowed|devTimeFormat=MMM dd yyyy HH:mm:ss src=192.168.64.22 dst=192.168.198.102 srcPort=59986 dstPort=2463 proto=6 devTime=Aug 31 2023 09:11:36 sender=Force-1-NDB node 1 action=Allow

EL MOUSTAPHA MOHAMED LEMINE TAHER
EL MOUSTAPHA MOHAMED LEMINE TAHER
FSM_FTNT
Staff
Staff

Are you able to use CEF format and provide a sample? Something has probably changed in the log format and we need to make an update.

Taher11
New Contributor III

Yes, I can, an update on what exactly?

 

Screenshot 2023-08-31 093227.png

 

EL MOUSTAPHA MOHAMED LEMINE TAHER
EL MOUSTAPHA MOHAMED LEMINE TAHER
FSM_FTNT
Staff
Staff

Can you send to me directly an export in CSV format of the forecpoint logs? A varied sample of logs will be best.

 

I can see that Forcepoint have changed their log format.

 

Thanks

Taher11
New Contributor III

Hello we have developed a new parser and the problem was resolved, thank you for your time 

EL MOUSTAPHA MOHAMED LEMINE TAHER
EL MOUSTAPHA MOHAMED LEMINE TAHER
Announcements

Welcome to your new Fortinet Community!

You'll find your previous forum posts under "Forums"