Skip to content

Commit

Permalink
update README.md
Browse files Browse the repository at this point in the history
  • Loading branch information
cweltPA committed Jul 10, 2024
1 parent bce5b49 commit 42ec1b5
Showing 1 changed file with 11 additions and 12 deletions.
23 changes: 11 additions & 12 deletions Packs/FortiGate/README.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
<~XSIAM>
# Fortigate

# Fortinet FortiGate
This pack includes Cortex XSIAM content.

Fortigate versions: 7.x
Expand All @@ -8,7 +9,7 @@ Fortigate versions: 7.x
You need to configure Fortigate to forward Syslog messages.

1. Log in to the FortiGate web interface using your admin credentials.
2. Open a CLI console by clicking the **_>** icon in the top right corner
2. Open a CLI console by clicking the **`_>`** icon in the top right corner
4. Run the following command:
```bash
config log syslogd setting
Expand All @@ -19,7 +20,7 @@ You need to configure Fortigate to forward Syslog messages.
set port <port_number>
```

More information can be found [here](https://docs.fortinet.com/document/fortigate/7.4.1/administration-guide/250999/log-settings-and-targets)
More information can be found [here](https://docs.fortinet.com/document/fortigate/7.4.4/administration-guide/250999/log-settings-and-targets).
## Collect Events from Vendor
In order to use the collector, use the [Broker VM](#broker-vm) option.

Expand All @@ -30,12 +31,10 @@ In order to use the collector, use the [Broker VM](#broker-vm) option.
### Broker VM
You will need to use the information described [here](https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Configure-the-Broker-VM).\
You can configure the specific vendor and product for this instance.
1. Navigate to **Settings** -> **Configuration** -> **Data Broker** -> **Broker VMs**.
2. Right-click, and select **Syslog Collector** -> **Configure**.
3. When configuring the Syslog Collector, set:
- vendor as Fortinet
- product as FortiGate
</~XSIAM>



1. Navigate to **Settings** &rarr; **Configuration** &rarr; **Data Broker** &rarr; **Broker VMs**.
2. Right-click, and select **Syslog Collector** &rarr; **Configure**.
3. When configuring the Syslog Collector, set the following:
- vendor as *Fortinet*.
- product as *FortiGate*.

</~XSIAM>

0 comments on commit 42ec1b5

Please sign in to comment.