Skip to main content

Site CollectorSite Collector Administration Guide

Set Up Fortinet Collector

Fortinet Collector is a customized Syslog Collector which is designed to fetch log data specifically encoded with Octet Counting framing strategy such as Fortinet in which a transport receiver uses a defined message length to delimit a syslog message.

Fortinet Collector (also called as Syslog with Octet Counting) fetches syslog logs from various sources and pushes the logs to Exabeam Security Operations Platform for further processing. The Fortinet Collector supports only TCP/TLS protocol. For pulling Fortinet data through UDP, use the Syslog Collector.

To set up the Fortinet collector:

  1. Log in to the Exabeam Security Operations Platform with your registered credentials.

  2. Navigate to Collectors > Site Collectors.

  3. Ensure that Site Collector is installed and in running state.

  4. On the Site Collector page, click the Collectors Library tab, then click Fortinet.

    Fortinet_1.png
  5. In the Definition section, enter the required information as follows.

    Fortinet_2.png
    • Collector Name – Specify a name for the Fortinet collector.

      Note

      Ensure that you specify different names for Site Collector instance and the Fortinet collector.

    • Site Collector Instance – Select the site collector instance for which you want to install the Fortinet collector.

    • Port – Enter the TCP port number of the Fortinet server, from the supported port range 1024 - 49151.

      Note

      If you use port 514, forward the port on the Site Collector VM and set up the Fortinet Collector with port 1514 or any other port from the supported port range.

  6. Click Next.

  7. In the Authentication section, select the required protocol: TCP. TCP helps for transmitting Syslog data over TCP securely and for ensuring reliable and ordered data transmission between networks. To configure a secure syslog ingestion, select TCP and enable the Secure Connection option.

    To enable secure and encrypted TLS communication between your Fortinet server and the Fortinet Collector, download the Exabeam generated security certificates. Click Default Certificate, and click Download Certificate. Then save and apply the downloaded certificates on your Fortinet server.

    Fortinet_3.png

    Note

    If you want to ingest Fortinet data via UDP, use the Syslog Collector.

  8. To set up the Fortinet collector, click Setup.

    The configuration for Fortinet Collector is complete. The collector is set up and ready to receive the logs pushed by Fortinet sources.

    Syslog_step3.png