This article helps you to connect your Fortinet FortiGate NGFW via SIEM to the Expel Workbench. The procedure is to port in logs by creating a new Syslog source, configuring that source in Workbench, then your Fortinet device in Workbench.
Note
Some steps in this procedure vary greatly depending upon the SIEM-based technology you use.
Step 1: Logging to a Desired SIEM
Refer to your SIEM documentation or work with your SIEM representative to port in Fortinet logs. You can also refer to the following web references for creating a new Syslog source:
Step 2: Configure the SIEM in Workbench
This link opens the Expel Knowledge Base section for connecting SIEM-based technology to Workbench. Follow the applicable article to configure your SIEM-based tech and confirm that Fortinet logs are flowing through and available.
Step 3: Configure Fortinet in Workbench
-
In a new browser tab, go to https://workbench.expel.io/settings/security-devices?setupIntegration=fortinet_via_siem.
-
Fill in the device fields like this:
-
For SIEM, select the SIEM that was onboarded in Step 2.
-
For Name, type the host name of the Fortinet device.
-
For Location, type the geographic location of the device.
-
-
Fill in the Connection Settings fields based on the SIEM you selected:
-
For Source category, type the Sumo Logic source category for this device.
-
For Source type, type the Splunk source type for this device.
-
For Resource group name, type the Secureonix resource group name for this device.
-
For Vendor, type either the Exabeam Fusion SIEM vendor or the Microsoft Sentinel device vendor for this device.
-
- Select Save.