Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
saharawolf
New Contributor

Log analysis with ManageEngine firewall analyzer !

Hello everyone, I used to have a fortianalyzer 800B to log and make reports for my fortigates. However, my 800B doesn' t support V5 firmware and thus it doesn' t analyze logs from upgraded firewalls. I' ve been looking for a workaround to get my logs analyzed and found the ManageEngine firewall analyzer witch support Fortigates (that' s what they say). I configured everything and get my forti sending logs to the analyzer but i found that the reports aren' t like what i expected (not like fortianalyzer ones). For example, i found that manageengine classes teamviewer or MS update or anything blocked as an attack !! that' s weird ! Have any one tried using manageengine ? Or can you tell me a suitable software to do this task like the fortianalyzer ? Thanks to everyone who would help. Regards
4 REPLIES 4
billp
Contributor

I assume you' ve looked at FortiCloud? That might be the least expensive solution if it works for you. If you have some facility with setting up a syslog server, I' ve found that Logstash can do a nice job of parsing the existing Fortigate logs. This is really a DIY approach to interpret logs, though, and not an out-of-the-box solution. It doesn' t generate reports as much as it allows you to create specific views into firewall activity. Still -- it has all the data from your logs. I' ve heard good things about the free Cyberoam Iview software, but have not used it. That' s probably similar to ManageEngine. Logmojo.com looks like a good non-free solution and is tailored for Fortigate. Hope that helps. I' m a big fan of Logstash, but it' s not for everyone.

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1
Nihas
New Contributor

Hi , You can try Cyber Roam Iview http://www.cyberoam-iview.org/
Nihas [\b]
Nihas [\b]
FortiAdam
Contributor II

I used ManageEngine for a short period of time and noticed the same issues. All of the denied UDP traffic that my firewalls were logging as locally denied was showing as " attack" traffic. You might consider LogMojo by Security Confidence as well. It' s a cloud based log analysis tool that you pay for based on the amount of storage you need.
Mark_Oakton
Contributor

logmojo works well on fortigate traffic
Infosec Partners
Infosec Partners
Labels
Top Kudoed Authors