As per the configuration above. This makes sure that each logs is sent
with the firewall IP address as the source. If you do not use this
configuration, then all logs are sent from the FAZ IP only. This would
consume a single device license. However,...
There is no best practice here. Both will achieve the same thing. It is
a design decision. Here are some things to consider: Maybe the firewalls
don't have access to FortiSIEM but FortiAnalyzer does. FortiAnalayzer
works best here. Do you need to fil...
Hi @Waloo5 FortiSIEM will use 1 device license per unique IP address. If
you use the above configuration, then each firewall will maintain its
unique IP address. Therefore, each firewall will use up 1 device
license.