Any QRADAR users in the forum?
One of the initial issues faced is that we want to have the VDOMs reported as separate devices. Any other company that already did some modification?
You can use the per-vdom syslog overrides to trick your system into seeing the traffic coming from different devices. If your SIEM doesn't have an interpreter that can use the vdom tags, it most likely uses the syslog source ip to identify devices- I've seen other products that do it similarly.
You can use the CLI commands "config log syslogd override-setting" and "set source-ip <ip address>" to do this. You set the parameter per vdom and the syslogs will appear to be coming from whatever ip address you choose instead of the management interface of the box. For sanity, you want to make sure to have each vdom source be an interface that actually exists on the vdom.
CISSP, NSE4
Thanks for the info.
Going to check it out.
What is the impact on performance on a 1500D with 10 VDOMs and around 700 to 1500 logs per second? Does it have an impact and will it be measurable and consistent?
But actually I was hoping that Fortinet creates a better DSM for QRADAR or maybe they have and all I need is to tweak it.
QRADAR is according to some Fortinet documents a supported SIEM, not sure who created the DSMs (IBM or Fortinet) and if they have they should include proper VDOM handling. Or at least explain how to use it.
I also have this issue with FAZ, as I would like to have a global view over multiple VDOMs and a per VDOM filter on FortiView. Today it seems not possible.
Your SIEM will receive traffic from the management IP of the Gate.
Splunk, for instance, will see the IP of the management interface and receive logs. From there it is set globally so you can definitely enjoy an overarching view between vdoms. They will send just the same.
At least this has been my experience.
Mike Pruett
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1114 | |
760 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.