FortiSIEM
FortiSIEM provides Security Information and Event Management (SIEM) and User and Entity Behavior Analytics (UEBA)
mbenvenuti
Staff
Staff
Article Id 379593
Description This article describes how to start creating a customized parser.
Scope FortiSIEM.
Solution

When it is required to create a new parser, it is a good practice to start from an existing parser with the below steps :

  • Go to the Admin -> Device support -> Parsers.
  • Disable the original system parser.
  • Clone and edit the cloned parser.
  • Add the required custom lines.
  • Validate.
  • Test using the sample provided.
  • Enable and apply this parser in GUI.