FortiSIEM Discussions
plip
New Contributor

FortiSiem - AIX server regstration

have you tried registering AIX server? we're able to configure syslog setting but AIX still not sending logs to Fortisiem.

1 Solution
premchanderr
Staff
Staff

Hi,

 

The IBM AIX server can be integrated via syslog , ssh and snmp. 

 

If syslogs are not reaching Fortisiem then it has to be checked on end device or network.  

 

You can take a packet capture to verify:

Collect a tcpdump on the FortiSiem using below commands (Leave it for 5mins) : 
# tcpdump -i any "host x.x.x.x" -vvv -w AIXserver.pcap //x.x.x.x --- is the server IP . Export the pcap and review.

Documentation Link:

https://docs.fortinet.com/document/fortisiem/7.0.0/external-systems-configuration-guide/125735/ibm-a...

Regards,
Prem Chander R

View solution in original post

3 REPLIES 3
premchanderr
Staff
Staff

Hi,

 

The IBM AIX server can be integrated via syslog , ssh and snmp. 

 

If syslogs are not reaching Fortisiem then it has to be checked on end device or network.  

 

You can take a packet capture to verify:

Collect a tcpdump on the FortiSiem using below commands (Leave it for 5mins) : 
# tcpdump -i any "host x.x.x.x" -vvv -w AIXserver.pcap //x.x.x.x --- is the server IP . Export the pcap and review.

Documentation Link:

https://docs.fortinet.com/document/fortisiem/7.0.0/external-systems-configuration-guide/125735/ibm-a...

Regards,
Prem Chander R
plip

using the tcpdump command aix is not sending logs to the siem. any ideas what can be checked on the end device? since the syslog config is pretty straightforward (*.* @IPadd) 

Is there any other sides that can be look into?

premchanderr

Hi @plip ,
If there are no traffic in tcpdump then it is network layer issue and further probe should be done via firewall or in network.   You can also try traceroute to the SIEM from end device.

Regards,
Prem Chander R
Announcements

Welcome to your new Fortinet Community!

You'll find your previous forum posts under "Forums"