Fortinet¶
Fortinet provides a rich stream of network telemetry which helps identify attackers in flight.
Data Types¶
- FORTINET_FIREWALL
Configuration¶
- In the FortiAnalyzer console, navigate to System Settings > Log Forwarding
- Click Create New in the toolbar
- Name the output "Cyderes"
- Select "Common Event Format (CEF)" for the Remote Server Type
- For the Server IP, enter in the IP of the CYCLOPS appliance
- For Sending Frequency, select "Real-time"
- Choose to send logs from "All FortiGates" with no filters
- Select OK to save the configuration