Flow Support
FortiSIEM supports NetFlow v5, NetFlow v9, IPFIX and sFlow. You need to configure any device to send traffic to FortiSIEM on these ports and FortiSIEM will automatically parse and handle the flows. No other configuration is required.
Flow traffic should be sent to the below specified ports.
Protocol / Port |
Network Flow |
---|---|
UDP / 2055 | NetFlow v5 and NetFlow v9 |
UDP / 2055 | Internet Protocol Flow Information Export (IPFIX) |
UDP / 6343 | sFlow |
If you want to send to another port, then you need to configure port translation NAT on FortiSIEM.