Fortinet FortiGate Firewall is a next-generation firewall (NGFW) that provides network security, threat prevention, and secure connectivity for organizations of all sizes. For detailed information refer to the Fortinet Firewall’s official documentation.
Integration Method: Data Collector (Syslog)
Tables: Detection Finding (2004), Network Activity (4001), HTTP Activity (4002), Authentication (3002)
This integration supports the following events.
Event | Description |
Application Control | Logs application signatures detected on the network, recording the application identity, risk level, and whether the traffic was allowed or blocked based on policy. |
IPS | Logs intrusion prevention signature matches, capturing detected attack patterns, exploits, or anomalous network behavior with the associated severity and action taken. |
Virus | Logs file-based threat detections, including infected files identified by the AV engine and files blocked by the Virus Outbreak Prevention service. |
WAF | Logs web application firewall events for inbound HTTP/HTTPS traffic, covering signature-based attack detections and HTTP constraint violations on requests and responses. |
Web Filter | Logs URL and domain categorization decisions, recording whether web access was allowed or blocked based on FortiGuard category ratings. |
Traffic | Logs network session flow records for forward, local, multicast, and sniffer traffic, capturing session details such as source/destination, protocol, bytes transferred, and final action. |
Authentication | Logs user authentication lifecycle events including successful logins, logouts, authentication timeouts, and admin session activity. |
This integration supports the following versions.
FortiOS Version | v7.4.11 |
Prerequisites
- The user should have access to the Fortinet Firewall portal.
- The user should have admin access to the Fortinet Firewall to update the Log Setting.
- The user should have access to the DataBee console.
Configuration overview
- Install Data Collector on a VM.
- Update Log Setting to forward logs to syslog server.
- Add the Fortinet Firewall in the DataBee console.
Install Data Collector on a VM
- To install a Data Collector on any VM, follow this documentation. Where all the guidelines are mentioned about the Data Collector.
- Note the IP of the VM on which Data collector is installed.
Fortinet Firewall Configuration for Log Settings
- Login to your Fortinet portal.
Navigate to Log & Report > Log Settings- Make sure the below log settings are configured
- Select Event logging and local traffic logging as per the requirements
- Make sure System logging is Enable
- Enter the IP address of the VM on which Data Collector is installed
Click on the Apply button- Navigate to Policy & Objects > Firewall Policy

- Check Security Profiles are applied to your policies and make sure required profiles are enabled. Make sure Log allowed traffic option is enabled.

DataBee Configuration
- Login to the DataBee UI, navigate to Data > Data Feeds and click the Add New Data Feed button.
Search for Fortinet Firewall and click on it as shown below.
- Click on the Data Collector collection method

- Click on the Syslog method.

- In configuration, enter feed contact information, and select the Data Collector.

- Confirm the following details:
- Format: syslog-rfc5424
- Mode: UDP
- Port: 514

- Click Submit.
Troubleshooting Tips
- If you are not able to see data being ingested, make sure data collector is installed successfully and IP of that VM is set in the Log Settings of the Fortinet Firewall. Make sure required security profiles are enabled, and Log allowed traffic is allowed.