- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to use credentials menu through collector?
When we add credentials in FortiSIEM admin settings, it only asks to map IP.
Same IP can belong to multiple clients also, But in mapping there is no option to select collector. So how to map credentials to correct device linked to correct collector.
Also do i need to allow supervisor to firewall port 22 if i want to add SSH credentials? This is not possible by allowing collector to firewall connection over port 22?
Solved! Go to Solution.
- Labels:
-
FortiSIEM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, you should to run the discovery from the correct organization.
You only mentioned SSH above. Did you also configure SNMP credentials. Did the test credentials option work? Did the discovery succeed for SNMP?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I don't have a collector in my lab but you should have a dropdown menu on the credentials page. It will be in the same place as the red square below.
If you select collector here, you only need to allow connections on tcp/22 from the collector.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This is snapshot from Global view with collector setup. No such option
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can you provide some more information about your setup please?
Is it service provider or enterprise setup?
How many collector have you registered?
If in service provide mode, are the collectors dedicated to an org or are they multi org collectors?
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Service Provider,
20 Collectors
No sharing of collectors, its dedicated.
Mean while instead of global view, i switched to individual organization view and added credentials. It went through collector, test was successful but then also no SNMP performance logs being reported.
Also not sure of the approach to add credentials is correct.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, you should to run the discovery from the correct organization.
You only mentioned SSH above. Did you also configure SNMP credentials. Did the test credentials option work? Did the discovery succeed for SNMP?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you @Richie_C it worked!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Great question! The issue with mapping credentials to the correct device linked to the appropriate collector can be tricky. Adding the ability to specify the collector would certainly streamline things. As for SSH credentials, allowing supervisor access to firewall port 22 seems to be a default requirement, but it’s worth exploring if collector-level access can achieve the same result.
