I'm running into a scenario where I need to push logs to AWS Cloud Watch from FortiGate and from there perform other activities.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
Please refer to https://docs.fortinet.com/document/fortigate-public-cloud/6.4.0/aws-administration-guide/154350/sett... hope this addresses your query.
It does give some thoughts, but I'm still wondering if I can push custom metrics like Memory to CloudWatch?
From Fortiweb support about the same question:
"After checking your query to send the logs to "AWS Cloud Watch", according to the following Amazon document,
Amazon CloudWatch Logs service allows you to collect and store logs from your own application and on-premises resources, which is available in the "Custom logs" category, you can use AWS Systems Manager to install a CloudWatch Agent, or you can use the PutLogData API action to easily publish logs.
Fortiweb supports "Syslog" and "SIEM" servers to store the logs remotely(referring to the attached picture).
For more information regarding this point, please check the "Configuring logging" section in the following document:
I would suggest checking whether CloudWatch could support getting logs from either Syslog or SIEM, then you may configure fwb to send logs to one of them."
I think it's a truly notable shortcoming not to be able to store WAF logs on CloudWatch for a product that is sold directly on the AWS marketplace.
The only alternative, quite ugly, is to install a syslog, send all the logs there and on the instance with the syslog enable the CloudWatch agent to write them back to CW Logs. But again, it's a bad method.
I agree, this is a huge limitation, and better integration into cloudwatch for FortiOS products is needed.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1634 | |
1063 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.