Fortinet black logo

Administration Guide

Integration with FortiAnalyzer

Copy Link
Copy Doc ID 94250e1c-2251-11ed-9eba-fa163e15d75b:449298
Download PDF

Integration with FortiAnalyzer

The steps in this topic assume the FortiDeceptor device has never to been connected to and has not been authorized by FortiAnalyzer.

To integrate FortiDeceptor with FortiAnalyzer:
  1. Configure the Log Servers in FortiDeceptor.
  2. Authorize FortiDeceptor in FortiAnalyzer.
  3. Create the FortiDeceptor security report in FortiAnalyzer.

1. Configure the Log Servers in FortiDeceptor

  1. In FortiDeceptor, go to Log > Log Servers and click Create New. The New Remote Log Server window opens.
  2. Set the Type to FortiAnalyzer and enter the Log Server Address.

  3. Configure the additional log server settings as required and click OK.

2. Authorize FortiDeceptor in FortiAnalyzer

Tooltip

Allow a minimum of five minutes before attempting to authorize FortiDeceptor in FortiAnalyzer.

  1. In FortiAnalyzer, go to Device Manager.
  2. Search for FortiDeceptor in the Unauthorized Devices list. It may take up to half an hour for the device to appear in the list.

  3. Select the device and click Authorize. The Authorize Device dialog opens.

  4. From the Add the following device(s) to ADOM list, select the ADOM you want to add the device to.

  5. Go to the ADOM's Device Manager and verify the FortiDeceptor is added.

  6. In the Logs column, the status will display a red dot until FortiDeceptor generates syslogs. A green dot indicates the device is connected and functioning properly.

  7. Go to Log View and select this FortiDeceptor to view the logs.

3. Create the FortiDeceptor security report in FortiAnalyzer

  1. In FortiAnalyzer, create the report template:
    1. Open the Reports module.
    2. Go to the Reports > Report Definitions > Templates.
    3. In the template list, select FortiDeceptor Default Report.

    4. In the toolbar, click Create New.
    5. Give the template a descriptive Name such as FortiDeceptor Security Report and from the Category dropdown, select Security.

    6. Configure the rest of the template settings as required and click OK. For information, see Creating report templates in the FortiAnalyzer Administration Guide.
  2. Create the report:
    1. Go to the Reports > Report Definitions.
    2. In the toolbar, click Report > Create New.
    3. Give the report a distinctive Name.
    4. Next to Create From, select Template and from the Select Template dropdown, select the FortiDeceptor template you created.

    5. Select the folder to save the report and click OK.

    For more information about creating reports in FortiAnalyzer see Reports in the FortiAnalyzer Administration Guide.

Integration with FortiAnalyzer

The steps in this topic assume the FortiDeceptor device has never to been connected to and has not been authorized by FortiAnalyzer.

To integrate FortiDeceptor with FortiAnalyzer:
  1. Configure the Log Servers in FortiDeceptor.
  2. Authorize FortiDeceptor in FortiAnalyzer.
  3. Create the FortiDeceptor security report in FortiAnalyzer.

1. Configure the Log Servers in FortiDeceptor

  1. In FortiDeceptor, go to Log > Log Servers and click Create New. The New Remote Log Server window opens.
  2. Set the Type to FortiAnalyzer and enter the Log Server Address.

  3. Configure the additional log server settings as required and click OK.

2. Authorize FortiDeceptor in FortiAnalyzer

Tooltip

Allow a minimum of five minutes before attempting to authorize FortiDeceptor in FortiAnalyzer.

  1. In FortiAnalyzer, go to Device Manager.
  2. Search for FortiDeceptor in the Unauthorized Devices list. It may take up to half an hour for the device to appear in the list.

  3. Select the device and click Authorize. The Authorize Device dialog opens.

  4. From the Add the following device(s) to ADOM list, select the ADOM you want to add the device to.

  5. Go to the ADOM's Device Manager and verify the FortiDeceptor is added.

  6. In the Logs column, the status will display a red dot until FortiDeceptor generates syslogs. A green dot indicates the device is connected and functioning properly.

  7. Go to Log View and select this FortiDeceptor to view the logs.

3. Create the FortiDeceptor security report in FortiAnalyzer

  1. In FortiAnalyzer, create the report template:
    1. Open the Reports module.
    2. Go to the Reports > Report Definitions > Templates.
    3. In the template list, select FortiDeceptor Default Report.

    4. In the toolbar, click Create New.
    5. Give the template a descriptive Name such as FortiDeceptor Security Report and from the Category dropdown, select Security.

    6. Configure the rest of the template settings as required and click OK. For information, see Creating report templates in the FortiAnalyzer Administration Guide.
  2. Create the report:
    1. Go to the Reports > Report Definitions.
    2. In the toolbar, click Report > Create New.
    3. Give the report a distinctive Name.
    4. Next to Create From, select Template and from the Select Template dropdown, select the FortiDeceptor template you created.

    5. Select the folder to save the report and click OK.

    For more information about creating reports in FortiAnalyzer see Reports in the FortiAnalyzer Administration Guide.