Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Kaspersky Security Center Integration
Hi,
I am trying to integrate Kaspersky Security Center with Fortisiem. I have enabled syslog on Kaspersky with port 514 UDP, but I couldn't find any logs on Fortisiem.
1 REPLY 1
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Yaseen,
Could you search by any hostname/IP or keyword in GUI and first check if logs are reaching SIEM.
Collect a tcpdump on the FortiSiem using below commands:
# tcpdump -i any "host x.x.x.x" -vvv -w Traffic.pcap //x.x.x.x --- is the server IP . Export the pcap and review it.
Regards,
Prem Chander R
Prem Chander R
