FortiEDR Central Manager logging
FortiEDR Central Manager can send its logs in Syslog format to FortiAnalyzer and the FortiAnalyzer parses the logs and inserts them into its SIEM database for event correlation and reporting.
To view FortiEDR logs in the Fabric log view:
-
FortiAnalyzer can collect FortiEDR Central Manager logs in Syslog.
Before this enhancement, FortiAnalyzer uses the syslog parser to parse FortiEDR Central Manager logs in SIEM.
FortiEDR Central Manager log messages and types did not display properly in the Fabric log view.
- After this enhancement, FortiAnalyzer includes a FortiEDR parser in the SIEM to parse FortiEDR Central Manager logs.
FortiAnalyzer can display FortiEDR Central Manager logs properly in the Fabric.