# Sending fortinalyzer logs to SIEM

**URL:** https://discuss.elastic.co/t/sending-fortinalyzer-logs-to-siem/314149
**Category:** Beats
**Tags:** filebeat
**Created:** [September 11, 2022, 7:44pm UTC](https://discuss.elastic.co/t/sending-fortinalyzer-logs-to-siem/314149 "2022-09-11T19:44:15Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![frank\_rib](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_rib/32/104372_2.png) [@frank\_rib](https://discuss.elastic.co/u/frank_rib)
#### Post date: [September 11, 2022, 7:44pm UTC](https://discuss.elastic.co/t/sending-fortinalyzer-logs-to-siem/314149/1 "2022-09-11T19:44:15Z")

</div>

Hello Community

Are the fortianalyzer supported by filebeat? if yes can you help me with its configuration at filebeat level by specifying the part to be addressed?

Thanks,

---

<div class="post-metadata">

### Author: ![frank\_rib](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_rib/32/104372_2.png) [@frank\_rib](https://discuss.elastic.co/u/frank_rib)
#### Post date: [September 12, 2022, 9:29pm UTC](https://discuss.elastic.co/t/sending-fortinalyzer-logs-to-siem/314149/2 "2022-09-12T21:29:01Z")

</div>

Hello Community,

Are there any expert can help me about that

Best rerads,

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [September 12, 2022, 10:29pm UTC](https://discuss.elastic.co/t/sending-fortinalyzer-logs-to-siem/314149/3 "2022-09-12T22:29:03Z")

</div>

Do you means the Logs forwarded by the Fortianalyzer or the fortianalyzer logs itself?

You can check the documentation of the [Fortinet](https://docs.elastic.co/en/integrations/fortinet) integration.

It looks like it is supported:

```auto
fortimanager dataset: supports Fortinet Manager/Analyzer logs.

```

---

<div class="post-metadata">

### Author: ![frank\_rib](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_rib/32/104372_2.png) [@frank\_rib](https://discuss.elastic.co/u/frank_rib)
#### Post date: [September 13, 2022, 8:07pm UTC](https://discuss.elastic.co/t/sending-fortinalyzer-logs-to-siem/314149/4 "2022-09-13T20:07:43Z")

</div>

Hello leandropjmp,

Thank you for the feedback. Sends logs received by fortianalyzer (fortinet products) to the SIEM ELK. is it supported?

Thanks,

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [September 13, 2022, 10:13pm UTC](https://discuss.elastic.co/t/sending-fortinalyzer-logs-to-siem/314149/5 "2022-09-13T22:13:56Z")

</div>

There are some integrations in the Elastic Agent.

Did you check the link in the previous post? Please, check the link for the documentation.

---

<div class="post-metadata">

### Author: ![frank\_rib](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_rib/32/104372_2.png) [@frank\_rib](https://discuss.elastic.co/u/frank_rib)
#### Post date: [September 13, 2022, 10:29pm UTC](https://discuss.elastic.co/t/sending-fortinalyzer-logs-to-siem/314149/6 "2022-09-13T22:29:37Z")

</div>

thank you for your reactivity, I saw it is compared to elastic agent. My need is to use filebeat module instead of elastic agent. The configuration made on my side at the fortinet module level: But I can't receive the logs at the SIEM level.

```auto
  fortimanager:
    enabled: true

    # Set which input to use between udp (default), tcp or file.
     var.input: udp
     var.syslog_host: 0.0.0.0
     var.syslog_port: 9004

```

Thanks

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [October 12, 2022, 12:30am UTC](https://discuss.elastic.co/t/sending-fortinalyzer-logs-to-siem/314149/7 "2022-10-12T00:30:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
