Hi,
We will send logs to FortiSiem from a device, but the default syslog ports are udp 9500. We were always collecting logs with the default 514 port. Is it possible to make this change?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi adem_netsys,
You can get the idea with the documentation for TCP, see here.
In general, you should have a look into the phoenix_config.txt file of your supervisor/collector. In there, you will find on which ports it should listen for which types for events. If you are using udp 9500 only, you can change the value directly. Otherwise, you might have to add it. If you need more assistance than my general information here, feel free to ask and I will look into the exact lines and syntax of the file.
Best,
Christian
Welcome to your new Fortinet Community!
You'll find your previous forum posts under "Forums"
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.