- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
FortiAnalyzer connection to SIEM
Hi there,
is there any (existing or planned) feature to be able to add the FortiAnalyzer to a SIEM (e.g. Microsoft Sentinel)?
Kind regards
- Labels:
-
FortiAnalyzer
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What do you mean? What is your use-case? You can forward FortiAnalyzer logs to any SIEM you wish.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I think Florian12 means he needs a fortianalyzer connecter for sentinel. There is one for the fortigate firewall, but I think it is not compatible with the FAZ logging. I would like the same thing because I don't want to sent all firewall logging to sentinel (because of costs, I have fortianalyzer for that) but I would like to be able to sent al my FAZ alerts and detections to sentinel.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Guys! Im a intern in a IT company working as a monitoring analyst with zabbix.
The company starts using FortiAnalyzer and FortiSOC to monitor log activities for our clients, currently the service that this company provides is installing Fortigate (Firewalls) in the clientes sites to comunicate with each other and use FortiAnalyzer to generate reports of unusual activites for the clients.
The thing is, I really want to work as a SOC analyst so I am trying to figure out a way to work with that in said company, and my first step is creating a SIEM enviroment when I have nothing to do in work, is there a way to use FortiAnalyzer and FortiSOC as a SIEM enviroment? Or shoud I try some know tools like Splunk or Elastic for the job?
Thanks in advance!
