Hello,
We need to integrate FortiSIEM-Cisco WSA/ESA through Syslog as per the official documents:
As we should call Log Name: IronPort-Mail OR IronPort-Web; we cant add another entry (Duplicate).
So, we need to know the Log type and the corresponding facility to send the concerned security logs.
Thanks in advance!
Hi @AliMhaerFathy ,
FortiSIEM can receive Syslog with any facility set from sending device configuration without any filters or log types. So, there would be no specification available from FortiSIEM side, but you can select both the parameters from Cisco device and send syslog accordingly.
Do note that depending on raw log and data parsed you might have to write a custom parser.
Welcome to your new Fortinet Community!
You'll find your previous forum posts under "Forums"
User | Count |
---|---|
72 | |
25 | |
15 | |
10 | |
10 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.