Integration with FortiAnalyzer
The steps in this topic assume the FortiDeceptor device has never to been connected to and has not been authorized by FortiAnalyzer.
To integrate FortiDeceptor with FortiAnalyzer:
- Configure the Log Servers in FortiDeceptor.
- Authorize FortiDeceptor in FortiAnalyzer.
- Create the FortiDeceptor security report in FortiAnalyzer.
1. Configure the Log Servers in FortiDeceptor
- In FortiDeceptor, go to Log > Log Servers and click Create New. The New Remote Log Server window opens.
- Set the Type to FortiAnalyzer and enter the Log Server Address.
- Configure the additional log server settings as required and click OK.
2. Authorize FortiDeceptor in FortiAnalyzer
Allow a minimum of five minutes before attempting to authorize FortiDeceptor in FortiAnalyzer. |
- In FortiAnalyzer, go to Device Manager.
- Search for FortiDeceptor in the Unauthorized Devices list. It may take up to half an hour for the device to appear in the list.
- Select the device and click Authorize. The Authorize Device dialog opens.
- From the Add the following device(s) to ADOM list, select the ADOM you want to add the device to.
- Go to the ADOM's Device Manager and verify the FortiDeceptor is added.
- In the Logs column, the status will display a red dot until FortiDeceptor generates syslogs. A green dot indicates the device is connected and functioning properly.
- Go to Log View and select this FortiDeceptor to view the logs.
3. Create the FortiDeceptor security report in FortiAnalyzer
- In FortiAnalyzer, create the report template:
- Open the Reports module.
- Go to the Reports > Report Definitions > Templates.
- In the template list, select FortiDeceptor Default Report.
- In the toolbar, click Create New.
- Give the template a descriptive Name such as
FortiDeceptor Security Report
and from the Category dropdown, select Security. - Configure the rest of the template settings as required and click OK. For information, see Creating report templates in the FortiAnalyzer Administration Guide.
- Create the report:
- Go to the Reports > Report Definitions.
- In the toolbar, click Report > Create New.
- Give the report a distinctive Name.
- Next to Create From, select Template and from the Select Template dropdown, select the FortiDeceptor template you created.
- Select the folder to save the report and click OK.
For more information about creating reports in FortiAnalyzer see Reports in the FortiAnalyzer Administration Guide.