we have a requirement to add the Zimbra email server to fortisiem. any best practice or any method that we need to follow to integrate the Zimbra email server into the fortisiem. Thank you.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi Ahamed, I think it will depend whether this is on premise or Cloud installation, I had a check of the on premise and looks like you will need to configure syslog to forward to FortiSIEM.
https://wiki.zimbra.com/wiki/Log_Files
There may be another step required to parser these log, but first is to get them into FortiSIEM.
Let us know how you get on.
Thanks
is there any log parser for Zimbra?
There isnt one out-the-box. Do you have some sample logs you can share?
Any updates ?
If you can provide logs, we will investigate a parser.
Welcome to your new Fortinet Community!
You'll find your previous forum posts under "Forums"
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.