| Description |
This article describes that it is sometimes required to manage FortiSIEM components (Supervisors, Collectors, and Workers) using an external IT Monitoring platform. By default, the SNMPD service is installed on any nodes but it is disabled. The following procedure can be used to monitor FortiSIEM components through SNMP Protocol. Typically, it is not required to open ports on local firewalld installed on any FortiSIEM components. |
| Scope | FortiSIEM. |
| Solution |
Restrict SNMP access:
Default SNMP behavior:
SNMP v1/v2C configuration: The following procedure can be used if the IT monitoring platform supports SNMP v1/v2C:
rocommunity <community> default
Below is an example:
systemctl start snmpd
Below is an example:
SNMP v3 configuration: The following procedure can be used if the IT monitoring platform supports SNMP v3:
systemctl stop snmpd
net-snmp-create-v3-user [-ro] [-A authpass] [-a MD5|SHA] [-X privpass][-x DES|AES] [username]
Below is an example:
Start the SNMPD service, and run the following commands:
systemctl start snmpd
Below is an example:
Limitations:
Best practice: SNMP monitoring should be used only as a complementary method for infrastructure-level monitoring when required by external tools. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.