Hi guys,
is it possible with the FortiAnalyzer to parse information out of a syslog, for example from a Sophos XG Firewall? Is there a site where i can find already written Log parsers? Or how do i write one?
We want to ingest Logs from different sources, Sophos, Juniper, Checkpoint, Palo Alto,... via syslog in FAZ and parse them, to run Event Handlers on those parsed logs. Is that even possible with FAZ?
Thanks for your answers :)
Hello @alled ,
FortiAnalyzer can only collect logs from Fortinet products. If you want to collect and parse logs from other devices, you can use an SIEM solution such as FortiSIEM.
Yes, You can add third party devices via syslog, the bad news is that you need to configure a JSON parser adhoc to ingest third party devices and match every field of the log.
There is little information for build a JSON parser for FAZ.
Hi,
Under (v7.4) Incidents & Events > Log Parser you can find the available ones.
https://docs.fortinet.com/document/fortianalyzer/7.4.2/administration-guide/353514/siem-log-parsers
User | Count |
---|---|
1922 | |
1144 | |
769 | |
447 | |
277 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.