FortiSandbox
FortiSandbox provides a solution to protect against advanced threats and ransomware for companies who don’t want to implement and maintain a sandbox environment on their own.
MFARRAG
Staff
Staff
Article Id 252908
Description

 

This article describes the case of FortiSandbox Integration with IBM Qradar SOC.

 

Scope

 

4.2.2.

 

Solution

 

1) From Log & report, add a new log server with type CEF and type port number 514 with the IP address for the IBM Qradar server.

 

1.PNG

 

2) Make sure FortiSandbox is working fine, and scan results are updated in Scan statistics.

 

8.PNG

 

3) Make sure the traffic UDP/514 is allowed in the intermediate devices like the firewall.

4) Use the below CLI command from the FortiSandbox console to verify the traffic towards SIEM/IBM Qradar:

 

>tcpdump -ni port 1 port 514 and host 192.168.1.1