Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
alled
New Contributor

Parse syslogs of different devices in FortiAnalyzer

Hi guys,

is it possible with the FortiAnalyzer to parse information out of a syslog, for example from a Sophos XG Firewall? Is there a site where i can find already written Log parsers? Or how do i write one?
We want to ingest Logs from different sources, Sophos, Juniper, Checkpoint, Palo Alto,... via syslog in FAZ and parse them, to run Event Handlers on those parsed logs. Is that even possible with FAZ?

Thanks for your answers :)

VidMate
2 REPLIES 2
ozkanaltas
Contributor III

Hello @alled ,

 

FortiAnalyzer can only collect logs from Fortinet products. If you want to collect and parse logs from other devices, you can use an SIEM solution such as FortiSIEM. 

 

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
seguridadinformatica
New Contributor

Yes, You can add third party devices via syslog, the bad news is that you need to configure a JSON parser adhoc to ingest third party devices and match every field of the log.
There is little information for build a JSON parser for FAZ.

Labels
Top Kudoed Authors