Home

Azure Sentinel - Connector for Fortinet

%3CLINGO-SUB%20id%3D%22lingo-sub-1005717%22%20slang%3D%22en-US%22%3EAzure%20Sentinel%20-%20Connector%20for%20Fortinet%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1005717%22%20slang%3D%22en-US%22%3E%3CP%20class%3D%22olark-visitor-message%22%3E%3CSPAN%3ETrying%20to%20connect%20Azure%20Sentinel%20for%20Fortinet%20on%20Linux%20proxy%20machine%20%3A%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22olark-visitor-message%22%3E%3CSPAN%3EWhen%20adding%20the%20sentinel%20connector%20for%20Fortinet%20-%20to%20act%20as%20a%20proxy%20for%20forwarding%20Fortinet%20logs%20-%20received%20the%20following%20error%20%3A%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3Ewhen%26nbsp%3B%20installing%20the%20syslog%20agent%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22olark-visitor-message%22%3E%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22olark-visitor-message%22%3E%3CSPAN%3E%26nbsp%3B%3A%20IOError%3A%20%5BErrno%202%5D%20No%20such%20file%20or%20directory%3A%20'%2Fetc%2Fopt%2Fmicrosoft%2Fomsagent%2Fxxxx%2Fconf%2Fomsagent.d%2Fsecurity_events.conf'%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22olark-visitor-message%22%3E%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22olark-visitor-message%22%3E%3CSPAN%3EVersion%20of%20python%20is%203.6.8%20and%20and%20its%20a%20linux%20Oracle%207.7%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22olark-visitor-message%22%3E%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22olark-operator-message%22%3E%3CSPAN%3EThe%20issue%20seems%20to%20be%20with%20the%20repository%20on%20Github%20as%20the%20error%20message%20says%20that%20the%20file%20or%20directory%20is%20not%20found%20%3F%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22olark-visitor-message%22%3E%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22olark-visitor-message%22%3E%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22olark-visitor-message%22%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1005717%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EConnector%20for%20Fortinet%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Egithub%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESentinel%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1006444%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20Sentinel%20-%20Connector%20for%20Fortinet%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1006444%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F456690%22%20target%3D%22_blank%22%3E%40SpringWater%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThis%20thread%20has%20been%20helpful%20in%20the%20past%20for%20some%20ideas%20to%20try%26nbsp%3B%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FAzure-Sentinel%2FFailed-to-configure-use-CEF-syslog-facility%2Fm-p%2F376735%23M130%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FAzure-Sentinel%2FFailed-to-configure-use-CEF-syslog-facility%2Fm-p%2F376735%23M130%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1006917%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20Sentinel%20-%20Connector%20for%20Fortinet%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1006917%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F456690%22%20target%3D%22_blank%22%3E%40SpringWater%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThe%20OMSAgent%20is%20not%20installed%20properly%20on%20the%20Operating%20System.%20Run%20the%20following%20command%20to%20install%20and%20test%20the%20installation.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EInstall%2Fupgrade%2Frepair%20the%20agent%3C%2FP%3E%0A%3CP%3E%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3Esudo%20wget%20%3CA%20href%3D%22https%3A%2F%2Fraw.githubusercontent.com%2FAzure%2FAzure-Sentinel%2Fmaster%2FDataConnectors%2FCEF%2Fcef_installer.py%26amp%3B%26amp%3B%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fraw.githubusercontent.com%2FAzure%2FAzure-Sentinel%2Fmaster%2FDataConnectors%2FCEF%2Fcef_installer.py%26amp%3B%26amp%3B%3C%2FA%3E%20python%20cef_installer.py%20%3CWORKSPACE_ID%3E%20%3CWORKSPACE_KEY%3E%3C%2FWORKSPACE_KEY%3E%3C%2FWORKSPACE_ID%3E%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3ECheck%2FTest%2FInstall%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3E%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3Esudo%20wget%20%3CA%20href%3D%22https%3A%2F%2Fraw.githubusercontent.com%2FAzure%2FAzure-Sentinel%2Fmaster%2FDataConnectors%2FCEF%2Fcef_troubleshoot.py%26amp%3B%26amp%3B%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fraw.githubusercontent.com%2FAzure%2FAzure-Sentinel%2Fmaster%2FDataConnectors%2FCEF%2Fcef_troubleshoot.py%26amp%3B%26amp%3B%3C%2FA%3E%20sudo%20python%20cef_troubleshoot.py%20%3CWORKSPACE_ID%3E%3C%2FWORKSPACE_ID%3E%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
SpringWater
Visitor

Trying to connect Azure Sentinel for Fortinet on Linux proxy machine :

When adding the sentinel connector for Fortinet - to act as a proxy for forwarding Fortinet logs - received the following error : when  installing the syslog agent

 

 : IOError: [Errno 2] No such file or directory: '/etc/opt/microsoft/omsagent/xxxx/conf/omsagent.d/security_events.conf'

 

Version of python is 3.6.8 and and its a linux Oracle 7.7 

 

The issue seems to be with the repository on Github as the error message says that the file or directory is not found ?

 

 

 

2 Replies

@SpringWater 

 

The OMSAgent is not installed properly on the Operating System. Run the following command to install and test the installation.

 

Install/upgrade/repair the agent

sudo wget https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/DataConnectors/CEF/cef_installer.py&& python cef_installer.py <Workspace_id> <Workspace_Key>

 

Check/Test/Install

sudo wget https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/DataConnectors/CEF/cef_troubleshoot.py... sudo python cef_troubleshoot.py <workspace_id>

 

 

 

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
46 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
29 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
13 Replies