Security Compliance

Integrate FortiGate firewalls with SolarWinds SEM

Configure your FortiGate firewall to send syslog events to the SEM.

First published date

10/9/2018 10:58 PM

Last published date

8/23/2023 2:58 AM

Overview

This article describes how to configure your Fortinet® FortiGate firewall to send syslog events to SolarWinds Security Event Manager (formerly Log & Event Manager). 


To integrate your FortiGate firewall with SolarWinds SEM: 

  1. Configure your FortiGate firewall settings. 
  2. Configure the FortiGate connector in your SEM Console.

Product section

Security Event Manager

Cause

N/A

Resolution

Configure your FortiGate firewall settings 

Configure the FortiGate firewall settings for your specific FortiOS operating system.

Note: 
*** We always recommend checking this on the Fortinet documentation website or ask assistance to the vendor to make sure all the commands and configuration are correct ***


Firewalls running FortiOS 4.x 

  1. Open your FortiGate Management Console.
  2. Navigate to Log & Report > Log Config > Log Settings. 
  3. Select the Syslog check box.
  4. Expand the Options section and complete all fields. 
    1. In the Name/IP field, enter the hostname or IP address of your SEM appliance.
    2. In the Port field, enter 514.
    3. In the Level field, select the logging level where FortiGate should generate log messages.

      SolarWinds recommends Level 6 - Information. This level provides the most comprehensive logging messages.

    4. In the Facility field, enter a specific syslog facility for the SEM appliance or accept the default.

      Do not select Enable CSV Format. Clear this option (if necessary).  

      The SEM connector matches the default value in FortiGate by default. If required, you can configure custom values in both areas. 

  5. Click Apply.

    Your firewall is configured. 


Firewalls running FortiOS 5.x 

In FortiOS 5.x, you can only define a syslog server using a command line. If you defined virtual domains (VDOMs), run through the appropriate command for each VDOM. 


The system includes three sets of syslog settings you need to consider before conducting an overwrite. SolarWinds recommends identifying these settings first before you continue. 

config log {syslogd | syslogd2 | syslogd3} setting

config log {syslogd | syslogd2 | syslogd3} setting

config log {syslogd | syslogd2 | syslogd3} setting

show

end


See the FortiGate FortiOS CLI Reference for 5.0 Guide located on the Fortinet website (Copyright © 2019 Fortinet, Inc. All Rights Reserved, available at http://www.fortinet.com, obtained on July 22, 2019) for information about the following setting:

{syslogd |  syslogd2 | syslogd3}


To configure your firewall running FortiOS 5.x, open a command line and execute the following: 

config global
config log syslogd2 setting 
set status enable
set csv disable
set server <sem><sem/></sem>
set source-ip <ip><ip/></ip>
end


See the FortiGate FortiOS CLI Reference for FortiOS 5.0 Guide for more information.

If no network/firewall related issue, you should be able to see the Log facility selected above ex:local7 growing on SEM side. This can be checked via Putty -> SEM -> appliance -> checklogs

For FortiOS 7.0.x
Refer to this guide below
https://docs.fortinet.com/document/fortigate/7.0.6/cli-reference/448620/config-log-syslogd-setting


Configure the FortiGate connector in your SEM Console 

After you configure your FortiGate firewall settings, configure the appropriate FortiGate connector in your SEM Console. 
Note: If you are running FortiOS 4.x, configure the FortiGate 2.8+ connector. If you are running FortiOS 5.x, configure the FortiGate 5.0+ connector. 

SEM HTML5 console (versions 6.6 and newer)

  1. In the SEM Events Console, navigate to Nodes > Manager Connectors.
  2. In the search box, enter Fortigate.
  3. Select the appropriate FortiGate connector for your FortiOS operating system, and then click Add connector.
  4. Enter a new name, or maintain the default.
  5. In the Log field, verify that the path is pointed to the local facility configured in your device syslog settings, and then click Add.
  6. Under Configured connectors, select the connector, and then click Start.


SEM Flash console

  1. Open your SEM Console and log in as an administrator.
  2. On the SEM toolbar, navigate to Manage > Appliances.
  3. In the Appliances screen, click the "gear" icon next to your appliance, and then select Connectors.
  4. In the Search field, enter Fortigate.
  5. In the Connectors screen, locate the appropriate FortiGate connector for your FortiOS operating system.
  6. Click the "gear" icon next to the appropriate connector, and then select New. 

    The Connector Configuration window appears. 

  7. In the Alias field, enter a custom name or accept the default name. 
  8. In the Log field, verify that the path is pointed to the local facility configured in your device syslog settings.
  9. When you are finished, click Save.
  10. Click the "gear" icon next to your new connector (highlighted with an icon in the Status column), and then select Start.
  11. To exit the Connector Configuration window, click Close. 

    Your FortiGate connector is configured in your SEM console. 


See Troubleshooting Network Devices Logging to SEM for information about troubleshooting connectors and logging devices. 

Disclaimer: Please note, any content posted herein is provided as a suggestion or recommendation to you for your internal use. This is not part of the SolarWinds software or documentation that you purchased from SolarWinds, and the information set forth herein may come from third parties. Your organization should internally review and assess to what extent, if any, such custom scripts or recommendations will be incorporated into your environment.  You elect to use third party content at your own risk, and you will be solely responsible for the incorporation of the same, if any.