Forum Discussion
BrunoFeltrin
Jul 26, 2021Copper Contributor
Azure Sentinel receiving log from Firewall Fortinet
Hi Team. We are using Azure Sentinel to receive logs from Fortinet Firewall via syslog, where it is forwarding all types of logs, how can I configure the syslog so that it forwards only important...
- Jul 28, 2021There is an option in Fortinet manager it self where you can create a rue by going to - System Settings > Log Forwarding. > Create New and click "On" log filter option > Log message that math >click on Any of the following Condition And create your own rule to forward any specific rule that you want to send. Thanks.
GBushey
Microsoft
Oct 17, 2023Have you tried to use syslog over the AMA to gather the data? You can then use DCRs to filter the data. https://learn.microsoft.com/en-us/azure/sentinel/forward-syslog-monitor-agent