FortiSIEM Discussions
khanchand
New Contributor II

Multiple azure tenant integration

Hi All,

 

We are running different tenant (Azure Intra ID), and want to integrate with FortiSIEM, we have created application and defined the credentials in FortiSIEM, and assigned in credential association tab as manage.office.com. Now the confusion is that we can not create the same entry with manage.office.com and we have assigned 2 credential at a time as it allows us to do so. But we can see logs from one of the tenant the other one is not showing any events.

 

Any one has any experience with this scenario before ?

 

TIA

1 Solution
FSM_FTNT
Staff
Staff

Hi,

Assuming it is this integration? https://docs.fortinet.com/document/fortisiem/7.1.3/external-systems-configuration-guide/514932/micro...

 

Could you please test the credentials again and collect the logs from the Collector that is performing the monitoring?

The log to collecto is /opt/phoenix/log/phoenix.log

Can you also screenshot your credential configuration.

It is probably best to raise a support case so that you can share the logs with us and reference this forum discussion in the ticket. We will look into it further.

View solution in original post

1 REPLY 1
FSM_FTNT
Staff
Staff

Hi,

Assuming it is this integration? https://docs.fortinet.com/document/fortisiem/7.1.3/external-systems-configuration-guide/514932/micro...

 

Could you please test the credentials again and collect the logs from the Collector that is performing the monitoring?

The log to collecto is /opt/phoenix/log/phoenix.log

Can you also screenshot your credential configuration.

It is probably best to raise a support case so that you can share the logs with us and reference this forum discussion in the ticket. We will look into it further.