Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mike-norrkoping
New Contributor

FortiSIEM log normalization

As we're expanding the use of our FortiSIEM, we've realized that not all logs are normalized properly, completely or in some case not at all. As we're fairly new to FortiSIEM, we're trying to figure out how to approach this - if we need to create our own normalization packages, if we can request them from Fortinet, if there are vendor-specific packages that can be requested or downloaded somewhere?

 

If we need to create our own, are there tools or do we copy an existing package and start working out what's what in the log we want to normalize?

Mike-Norrkoping
Mike-Norrkoping
3 REPLIES 3
Anthony_E
Community Manager
Community Manager

Hello Mike,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

Hello Mike,

 

We are still looking for someone to help you.

We will come back to you ASAP.


Regards,

Anthony-Fortinet Community Team.
gfleming
Staff
Staff

Here's some info on how to create your own parsers: https://help.fortinet.com/fsiem/6-7-4/Online-Help/HTML5_Help/Configuring_parsers.htm

Cheers,
Graham
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors