FortiGate Firewall log integration issues #11995
-
Version2.4.30 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeStandalone Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU6 RAM64GB Storage for /500GB Storage for /nsm2TB Network Traffic Collectiontap Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsYes, there are additional clues in /opt/so/log/ (please provide detail below) DetailAdditional Info: Fortigate version: 7.x errors found in
I'm currently having issues ingesting logs from my onprem fortigate, tcpdump is showing to me that the fortigate is sending the logs, but SO is not processing it I tried doing this #11730 (comment) and adding the following rule to the final pipeline definition
I tried having just the one in the local folder having the rule, I tried just having the one in the default folder having the rule, I tried them both with the rule added, even after service and/or physical machine restart I'm still getting the Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 6 replies
-
I ended up changing the mapping of the integration since the what I did:
I am personally not sure if this is the "correct" way to fix this issue, so I'm hoping the SO maintainers can comment below whether doing this is advisable or not. But now my log are getting processed by SO. edit: if you stumbled onto this post, please check the settings above again after updating SO to a new version, it may have reverted to the old value edit 2: If you are from a version of SO earlier than 2.4.50 and updated to 2.4.50 or greater, but still seeing the module persisting with the old value, you need to remove and add the |
Beta Was this translation helpful? Give feedback.
-
This did not work for me so am still searching for a way to get these logs to be "detected" by SO after they are clearing arriving on the box with tcpdump showing them. |
Beta Was this translation helpful? Give feedback.
I ended up changing the mapping of the integration since the
set
rule in the pipeline mentioned above does not seem to be working for mewhat I did:
Fortinet FortiGate Firewall Logs
Integration policies
, select your relevant integrationadvanced options
under your relevant method of sending the logs (in my case it is under the UDP section since that is how my FG is sending the logs)logs-fortinet_fortigate.log@package
-> click on the magnifying glassfortinet
->fortinet_fortigate
Review
…