This article describes the case of FortiSandbox Integration with IBM Qradar SOC.
4.2.2.
1) From Log & report, add a new log server with type CEF and type port number 514 with the IP address for the IBM Qradar server.
2) Make sure FortiSandbox is working fine, and scan results are updated in Scan statistics.
3) Make sure the traffic UDP/514 is allowed in the intermediate devices like the firewall.
4) Use the below CLI command from the FortiSandbox console to verify the traffic towards SIEM/IBM Qradar:
>tcpdump -ni port 1 port 514 and host 192.168.1.1
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.