FortiSIEM Discussions
ManuelRodriguez
New Contributor

MAC to Vendor

Hi there,

is there any chance to show the mac vendor of a mac inside an event?

I can see there is a MACByVendor.csv, a MACByVendor.txt and a MACByVendorGroup.csv under /opt/phoenix/data-definition, but have no clue if or how to use it.

Wonder why this is not correlated by default, like i.e. GEO IP.

Regards
Manuel

2 REPLIES 2
DanielHanman
Staff
Staff

Hi Manuel,

I checked on this internally, this list is not used within FortiSIEM currently. I am looking into a workaround using parser customization and the code attribute lookups.

Thanks

Dan

------------------------------
Daniel
FortiSIEM Product Manager
------------------------------
-------------------------------------------
Original Message:
Sent: Feb 12, 2021 06:01 AM
From: Manuel Rodriguez
Subject: MAC to Vendor

Hi there,

is there any chance to show the mac vendor of a mac inside an event?

I can see there is a MACByVendor.csv, a MACByVendor.txt and a MACByVendorGroup.csv under /opt/phoenix/data-definition, but have no clue if or how to use it.

Wonder why this is not correlated by default, like i.e. GEO IP.

Regards
Manuel

ManuelRodriguez

Hi, 

Parser would be perfect. Want to use it for a customised DHCP Parser and see which Vendor gets DHCPNACK.

Regards
Manuel-------------------------------------------
Original Message:
Sent: Mar 15, 2021 09:38 AM
From: Daniel Hanman
Subject: MAC to Vendor

Hi Manuel,

I checked on this internally, this list is not used within FortiSIEM currently. I am looking into a workaround using parser customization and the code attribute lookups.

Thanks

Dan

------------------------------
Daniel
FortiSIEM Product Manager
------------------------------

Original Message:
Sent: Feb 12, 2021 06:01 AM
From: Manuel Rodriguez
Subject: MAC to Vendor

Hi there,

is there any chance to show the mac vendor of a mac inside an event?

I can see there is a MACByVendor.csv, a MACByVendor.txt and a MACByVendorGroup.csv under /opt/phoenix/data-definition, but have no clue if or how to use it.

Wonder why this is not correlated by default, like i.e. GEO IP.

Regards
Manuel