FortiSIEM Discussions
Taher11
New Contributor III

Forcepoint NGFW Integration with Fortisiem

I succeeded to forward logs from the forcepoint NGFW to fortiSiem but all the event types received are unknown " unknown event type".

 

FortiSIEM , #Forcepoint

 

   

EL MOUSTAPHA MOHAMED LEMINE TAHER
EL MOUSTAPHA MOHAMED LEMINE TAHER
1 Solution
Taher11
New Contributor III

Hello we have developed a new parser and the problem was resolved, thank you for your time 

EL MOUSTAPHA MOHAMED LEMINE TAHER

View solution in original post

EL MOUSTAPHA MOHAMED LEMINE TAHER
6 REPLIES 6
FSM_FTNT
Staff
Staff

Are the events being sent in CEF format?

 

Can you share some sample events so that we can see what the issue is?

 

This is a sample event format that FortiSIEM expects to receive:

 

<6>CEF:0|FORCEPOINT|Alert|6.0.1|71257|TCP_Segment-SYN-No-Options|0|spt=2890 deviceExternalId=FW2 node 1 dmac=00:50:56:86:5E:16 dst=192.168.91.67 app=TCP/30152 rt=Sep 22 2016 23:38:00 deviceFacility=Packet filter act=Terminate deviceInboundInterface=2 proto=6 dpt=30152 src=192.168.155.35 dvc=192.168.94.51 dvchost=192.168.94.51 smac=00:10:DB:FF:10:01 cs1Label=RuleId cs1=97.0

Taher11
New Contributor III

We are using the LEEF format, but even if we change it to CEF the event type remains unkown.

 

<6>LEEF:1.0|Forcepoint|Firewall|7.0.2|Connection_Allowed|devTimeFormat=MMM dd yyyy HH:mm:ss src=192.168.64.22 dst=192.168.198.102 srcPort=59986 dstPort=2463 proto=6 devTime=Aug 31 2023 09:11:36 sender=Force-1-NDB node 1 action=Allow

EL MOUSTAPHA MOHAMED LEMINE TAHER
EL MOUSTAPHA MOHAMED LEMINE TAHER
FSM_FTNT
Staff
Staff

Are you able to use CEF format and provide a sample? Something has probably changed in the log format and we need to make an update.

Taher11
New Contributor III

Yes, I can, an update on what exactly?

 

Screenshot 2023-08-31 093227.png

 

EL MOUSTAPHA MOHAMED LEMINE TAHER
EL MOUSTAPHA MOHAMED LEMINE TAHER
FSM_FTNT
Staff
Staff

Can you send to me directly an export in CSV format of the forecpoint logs? A varied sample of logs will be best.

 

I can see that Forcepoint have changed their log format.

 

Thanks

Taher11
New Contributor III

Hello we have developed a new parser and the problem was resolved, thank you for your time 

EL MOUSTAPHA MOHAMED LEMINE TAHER
EL MOUSTAPHA MOHAMED LEMINE TAHER