Does Azure Sentinel support CSV format for FortiMail logs?

Highlighted
Contributor

Hi Everyone,

 

I wanted to know whether Azure Sentinel supports CSV format for FortiMail logs. I can see an option of enabling CSV format while configuring the remote logging on FortiMail. 

 

Please let me know whether I have to enable CSV format and Azure Sentinel have parsers for the same.

 

Regards,

Mitesh Agrawal 

1 Reply
Highlighted
I don't know Fortimail but if the logs are on or can be sent to server with the Microsoft management agent (MMA) that Sentinel uses, you could potentially use the Custom Log feature. If not then logstash, logic apps or an Azure function?