Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ted_barker
New Contributor

IBM Qradar, experienced users? What custom tweaking done etc.

We use IBM Qradar and I saw that they have a FortiGate DSM that tries to interpret Fortigate syslogs. Usually those are only basics and many input fields are not properly mapped, one of the things I checked immediately, was on how they identify the vdom's. And it looks like they did not define this as a property. Has anyone experience using Qradar with FortiGate and what custom tweaking did they do? What is the best log guide available? Detailed description of messages and what they mean?
4 REPLIES 4
ted_barker
New Contributor

Any QRADAR users in the forum?

 

One of the initial issues faced is that we want to have the VDOMs reported as separate devices. Any other company that already did some modification?

Kenundrum

You can use the per-vdom syslog overrides to trick your system into seeing the traffic coming from different devices. If your SIEM doesn't have an interpreter that can use the vdom tags, it most likely uses the syslog source ip to identify devices- I've seen other products that do it similarly.

You can use the CLI commands "config log syslogd override-setting" and "set source-ip <ip address>" to do this. You set the parameter per vdom and the syslogs will appear to be coming from whatever ip address you choose instead of the management interface of the box. For sanity, you want to make sure to have each vdom source be an interface that actually exists on the vdom.

CISSP, NSE4

 

CISSP, NSE4
ted_barker

Thanks for the info.

 

Going to check it out.

 

What is the impact on performance on a 1500D with 10 VDOMs and around 700 to 1500 logs per second? Does it have an impact and will it be measurable and consistent?

 

But actually I was hoping that Fortinet creates a better DSM for QRADAR or maybe they have and all I need is to tweak it.

 

QRADAR is according to some Fortinet documents a supported SIEM, not sure who created the DSMs (IBM or Fortinet) and if they have they should include proper VDOM handling. Or at least explain how to use it.

 

I also have this issue with FAZ, as I would like to have a global view over multiple VDOMs and a per VDOM filter on FortiView. Today it seems not possible.

MikePruett

Your SIEM will receive traffic from the management IP of the Gate.

 

Splunk, for instance, will see the IP of the management interface and receive logs. From there it is set globally so you can definitely enjoy an overarching view between vdoms. They will send just the same.

At least this has been my experience.

Mike Pruett Fortinet GURU | Fortinet Training Videos
Labels
Top Kudoed Authors