I use my FortiAnalyzer (7.4.8) as a "poor man" syslog server and am trying to see if I can incorporate logging from Cisco Umbrella. Cisco Umbrella only sends to AWS S3 storage and I have the path and keys for said bucket. I saw where FortiSIEM has said functionality, but I don't own that product... so seeing if there is a way to handle this via FortiAnalyzer in any form or fashion. This might end up being my final push point if it cannot, to go with something more dedicated as my new syslog platform.
Solved! Go to Solution.
Hi Kajun
Late FortiAnalyzer version includes SIEM capabilities that can handle logs from third party products.
https://docs.fortinet.com/document/fortianalyzer/7.6.0/security-operations-architecture/779526/siem
Hope it helps.
Hi Kajun
Late FortiAnalyzer version includes SIEM capabilities that can handle logs from third party products.
https://docs.fortinet.com/document/fortianalyzer/7.6.0/security-operations-architecture/779526/siem
Hope it helps.
Thanks for that. I'm going to further this up the food chain with my territory sales support engineer. It looks like 7.6.x out the box handles all of the Forti products for the most part plus Windows, Ubuntu, Apache, and a few others. The SOC Automation Service license adds a bunch of additional log parsers, but Umbrella is not listed... yet??? But a few other Cisco products are... hopefully it's something coming down the pipe. Thanks again to know what "rabbit hole" to jump down.
| User | Count |
|---|---|
| 2823 | |
| 1431 | |
| 812 | |
| 787 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.