FortiSIEM Discussions
Yaseen1
New Contributor

Kaspersky Security Center Integration

Hi, 

I am trying to integrate Kaspersky Security Center with Fortisiem. I have enabled syslog on Kaspersky with port 514 UDP, but I couldn't find any logs on Fortisiem.

1 REPLY 1
premchanderr
Staff
Staff

Hi Yaseen,

Could you search by any hostname/IP or keyword in GUI and first check if logs are reaching SIEM.

 

Collect a tcpdump on the FortiSiem using below commands:
# tcpdump -i any "host x.x.x.x" -vvv -w Traffic.pcap //x.x.x.x --- is the server IP . Export the pcap and review it.

 

Regards,
Prem Chander R