DOCUMENT LIBRARY
DOCUMENT LIBRARY
Products
Best Practices
Hardware Guides
Products A-Z
Summary
By Solution
By 4D Pillars
By Cloud
Secure Networking
Unified SASE
Security Operations
Secure SD-WAN
Secure Access Service Edge (SASE)
ZTNA
LAN Edge
Identity and Access Management
Next Generation Firewall
Public Cloud
Private Cloud
FortiCloud
Secure Networking
Hybrid Mesh Firewall
FortiGate/ FortiOS
FortiGate-5000
/
6000
/
7000
NOC Management
FortiManager
/
FortiManager Cloud
Managed Fortigate Service
LAN
FortiSwitch
FortiAP / FortiWiFi
FortiEdge Cloud
FortiNAC-F
WAN
Secure SD-WAN
FortiExtender
More >>
Unified SASE
Single Vendor SASE
FortiSASE
Secure SD-WAN
Zero Trust Network Access (ZTNA)
FortiProxy
FortiMonitor
Cloud Network Security
FortiGate Public Cloud
FortiGate Private Cloud
FortiGate CNF
FortiFlex
Lacework FortiCNAPP
Secure Endpoint Connectivity
FortiClient
/
FortiClient Cloud
Web Application / API Protection
FortiWeb
FortiADC
FortiDAST
More >>
Security Operations
Security Operations Automation
FortiAnalyzer
/
FortiAnalyzer Cloud
FortiSIEM
/
FortiSIEM Cloud
FortiSOAR
SOC-as-a-Service (SOCaaS)
Identity
FortiAuthenticator
FortiTrust Identity
FortiPAM
Early Detection & Prevention
FortiSandbox
/
FortiSandbox Cloud
FortiNDR
FortiDeceptor
FortiRecon
More >>
Secure Networking
Hybrid Mesh Firewall
FortiGate/ FortiOS
FortiGate-5000
/
6000
/
7000
NOC Management
FortiManager
/
FortiManager Cloud
Managed Fortigate Service
FortiAIOps
LAN
FortiSwitch
FortiAP / FortiWiFi
FortiAP-U Series
FortiEdge Cloud
FortiNAC-F
WAN
Secure SD-WAN
FortiExtender
Communication & Surveillance
FortiVoice
/
FortiVoice Cloud
FortiFone
FortiCamera
FortiRecorder
FortiCentral
Unified SASE
Single Vendor SASE
FortiSASE
Secure SD-WAN
Zero Trust Network Access (ZTNA)
FortiProxy
FortiMonitor
Secure Endpoint Connectivity
FortiClient
/
FortiClient Cloud
Cloud Network Security
FortiGate Public Cloud
FortiGate Private Cloud
FortiGate CNF
FortiFlex
Cloud-Native Security
Lacework FortiCNAPP
FortiDevSec
Web Application / API Protection
FortiWeb
FortiADC
FortiDAST
Security Operations
Security Operations Automation
FortiAnalyzer
/
FortiAnalyzer Cloud
FortiSIEM
/
FortiSIEM Cloud
FortiSOAR
Endpoint
FortiClient
/
FortiClient Cloud
FortiEDR/XDR
Data Protection
FortiDLP
FortiDLP Agent
FortiDLP Policies
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken
/
FortiToken Cloud
FortiPAM
Email
FortiMail
FortiPhish
Early Detection & Prevention
FortiSandbox
/
FortiSandbox Cloud
FortiNDR
FortiDeceptor
FortiRecon
Expert Services
SOC-as-a-Service (SOCaaS)
Edge Firewall
FortiGate/FortiOS
FortiGate-5000
/
6000
/
7000
FortiGate Public Cloud
FortiGate Private Cloud
Orchestration & management
FortiManager
/
FortiManager Cloud
FortiAnalyzer
/
FortiAnalyzer Cloud
Overlay-as-a-Service
SD Branch
FortiSwitch
FortiAP / FortiWiFi
FortiExtender
/
FortiExtender Cloud
Application Delivery
FortiADC
/
FortiGSLB
Single Vendor SASE
FortiSASE
Secure Endpoint Connectivity
FortiClient
/
FortiClient Cloud
Secure Private Access
Secure SD-WAN
Zero Trust Network Access (ZTNA)
Thin Edge
FortiGate/ FortiOS
FortiAP / FortiWiFi
FortiExtender
/
FortiExtender Cloud
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken Cloud
FortiToken
Application Gateway
FortiGate/ FortiOS
FortiProxy
FortiADC
/
FortiGSLB
Enterprise Asset Management
FortiClient EMS
Endpoint Agent
FortiClient
/
FortiClient Cloud
Agentless Security Posture
FortiNAC-F
FortiSIEM
/
FortiSIEM Cloud
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken Cloud
FortiToken
Wireless
FortiAP / FortiWiFi
FortiAP-U Series
FortiGate Cloud
Switching
FortiSwitch
FortiEdge Cloud
FortiNAC-F
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken Cloud
FortiToken
Privilege Acccess Management
FortiPAM
Next Generation Firewall
FortiGate / FortiOS
FortiGate-5000
/
6000
/
7000
FortiGate Public Cloud
FortiGate Private Cloud
Orchestration & management
FortiManager
/
FortiManager Cloud
FortiAnalyzer
/
FortiAnalyzer Cloud
Expert Services
SOC-as-a-Service (SOCaaS)
Managed Fortigate Service
All
FortiADC Public Cloud
FortiAnalyzer Public Cloud
FortiAuthenticator Public Cloud
FortiDeceptor Public Cloud
FortiGate Public Cloud
FortiIsolator Public Cloud
FortiManager Public Cloud
FortiNDR Public Cloud
FortiPAM Public Cloud
FortiPortal Public Cloud
FortiProxy Public Cloud
FortiSandbox Public Cloud
FortiTester Public Cloud
FortiVoice Public Cloud
FortiWeb Manager Public Cloud
FortiWeb Public Cloud
All
FortiADC Private Cloud
FortiAnalyzer BigData Private Cloud
FortiAnalyzer Private Cloud
FortiAuthenticator Private Cloud
FortiDeceptor Private Cloud
FortiGate Private Cloud
FortiManager Private Cloud
FortiNDR Private Cloud
FortiPAM Private Cloud
FortiProxy Private Cloud
FortiSandbox Private Cloud
FortiTester Private Cloud
FortiVoice Private Cloud
FortiWeb Manager Private Cloud
FortiWeb Private Cloud
Account Management
FortiCloud Services
SAAS Management
FortiGate Cloud
FortiEdge Cloud
FortiEdge Cloud
FortiExtender Cloud
FortiPresence Cloud
FortiToken Cloud
FortiTrust Identity
FortiZTP
FortiCamera Cloud
SAAS Application Security
FortiWeb Cloud
FortiGSLB
FortiCASB
FortiCNP
FortiInsight
FortiPhish
FortiGate CNF
Managed Services
SOC-as-a-Service (SOCaaS)
Managed Fortigate Service
Platform as a service (PAAS)
FortiSASE
FortiAnalyzer Cloud
FortiManager Cloud
FortiClient Cloud
FortiSandbox Cloud
FortiMail Cloud
FortiSOAR Cloud
Other SAAS Services
Overlay-as-a-Service
FortiRecon
FortiConverter
ForiIPAM
FortiFlex
FortiCare Elite
4D Resources
Solution Hubs
Define, design, deploy, demo
4D Pillars
Secure SD-WAN
Zero Trust Network Access
Wireless
Switching
Secure Access Service Edge
Identity and Access Management
Next Generation Firewall
Curated Links by Solution
Cloud
FortiCloud
Public & Private Cloud
Popular Solutions
Secure SD-WAN
Zero Trust Network Access
Secure Access
Security Fabric
Tele-Working
Multi-Factor Authentication
FortiASIC
Operational Technology
MSSP
Next Generation Firewall
FortiAnalyzer
FortiAnalyzer Big-Data
FortiADC
FortiAP / FortiWiFi
FortiAP U-Series
FortiAuthenticator
FortiCache
FortiCarrier
FortiController
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiExtender
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiHypervisor
FortiIsolator
FortiMail
FortiManager
FortiNAC
FortiNDR
FortiProxy
FortiRecorder
FortiGate
FortiRPS
FortiSandbox
FortiSIEM
FortiSwitch
FortiTester
FortiToken
FortiVoice
FortiWAN
FortiWeb
FortiWLC
FortiWLM
AscenLink
AV Engine
AWS Firewall Rules
Container FortiOS
FortiADC
FortiADC E Series
FortiADC Manager
FortiADC Private Cloud
FortiADC Public Cloud
FortiAIOps
FortiAnalyzer
FortiAnalyzer BigData
FortiAnalyzer BigData Private Cloud
FortiAnalyzer Cloud
FortiAnalyzer Private Cloud
FortiAnalyzer Public Cloud
FortiAP / FortiWiFi
FortiAP-U Series
FortiAuthenticator
FortiAuthenticator Private Cloud
FortiAuthenticator Public Cloud
FortiAuthProxy
FortiBalancer
FortiBranchSASE
FortiBridge
FortiCache
FortiCamera
FortiCamera Cloud
FortiCare Elite
FortiCarrier
FortiCASB
FortiCentral
FortiClient
FortiClient Cloud
FortiCloud Services
FortiCNP
FortiConnect
FortiController
FortiConverter Service
FortiConverter Tool
FortiCore
FortiCSPM
FortiCWP
FortiDAST
FortiDB
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiDeceptor DaaS
FortiDeceptor Private Cloud
FortiDeceptor Public Cloud
FortiDevSec
FortiDLP
FortiDLP Agent
FortiDLP Policies
FortiDNS
FortiEdge Cloud
FortiEDR/XDR
FortiEndpoint
FortiExplorer
FortiExplorer Go
FortiExtender
FortiFlex
FortiFone
FortiGate / FortiOS
FortiGate Cloud
FortiGate CNF
FortiGate Private Cloud
FortiGate Public Cloud
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiGate-as-a-Service
FortiGSLB
FortiGuard Advanced Bot Protection
FortiGuest
FortiHypervisor
FortiInsight
FortiInsight Cloud
FortiIPAM
FortiIsolator
FortiIsolator Public Cloud
FortiLAN Cloud
FortiMail
FortiMail Cloud
FortiManager
FortiManager Cloud
FortiManager Private Cloud
FortiManager Public Cloud
FortiMonitor
FortiNAC
FortiNAC-F
FortiNDR
FortiNDR (on-premise) Private Cloud
FortiNDR (on-premise) Public Cloud
FortiNDR Cloud
FortiNDR Cloud Sensors
FortiPAM
FortiPAM Private Cloud
FortiPAM Public Cloud
FortiPhish
FortiPlanner
FortiPolicy
FortiPortal
FortiPortal Public Cloud
FortiPresence
FortiPresence VM
FortiProxy
FortiProxy Private Cloud
FortiProxy Public Cloud
FortiRecon
FortiRecorder
FortiRPS
FortiSandbox
FortiSandbox Cloud
FortiSandbox Private Cloud
FortiSandbox Public Cloud
FortiSASE
FortiScanner
FortiSIEM
FortiSIEM Cloud
FortiSOAR
FortiSOAR Cloud
FortiSRA
FortiSwitch
FortiSwitch Manager
FortiTap
FortiTester
FortiTester Private Cloud
FortiTester Public Cloud
FortiToken
FortiToken Cloud
FortiTrust Identity
FortiVoice
FortiVoice Cloud
FortiVoice Private Cloud
FortiVoice Public Cloud
FortiWAN
FortiWAN Controller
FortiWeb
FortiWeb Cloud
FortiWeb Manager Private Cloud
FortiWeb Manager Public Cloud
FortiWeb Private Cloud
FortiWeb Public Cloud
FortiWLM
FortiZTP
IPS Engine
Lacework FortiCNAPP
Managed FortiGate Service
Overlay-as-a-Service
Security Awareness and Training
SOCaaS
Wireless Controller
Search documents and hardware ...
External Systems Configuration Guide
FortiSIEM External Systems Configuration Guide Online
Change Log
TABLE OF CONTENTS
Overview
FortiSIEM Port Usage
Supported Devices and Applications by Vendor
Applications
Application Server
Apache Tomcat
IBM WebSphere
Microsoft ASP.NET
Oracle GlassFish Server
Oracle WebLogic
Redhat JBOSS
Authentication Server
Cisco Access Control Server (ACS)
Cisco Duo
Cisco Identity Solution Engine (ISE)
CyberArk Password Vault
Fortinet FortiAuthenticator
Juniper Networks Steel-Belted RADIUS
Microsoft Internet Authentication Server (IAS)
Microsoft Network Policy Server (RAS VPN)
OneIdentity Safeguard
Vasco DigiPass
Database Server
IBM DB2 Server
Microsoft SQL Server
MySQL Server
Oracle Database Server
DHCP and DNS Server
Infoblox DNS/DHCP
ISC BIND DNS
Linux DHCP
Microsoft DHCP (2003, 2008)
Microsoft DNS (2003, 2008)
Directory Server
Microsoft Active Directory
Document Management Server
Microsoft SharePoint
Healthcare IT
Epic EMR/EHR System
Mail Server
Microsoft Exchange
Management Server/Appliance
Cisco Application Centric Infrastructure (ACI)
FortiInsight
Fortinet FortiManager
HPE Integrated Lights-Out (iLO)
VMware NSX for vSphere
Remote Desktop
Citrix Receiver (ICA)
Source Code Control
GitHub
GitLab API
GitLab CLI
Unified Communication Server
Avaya Call Manager
Cisco Call Manager
Cisco Contact Center
Cisco Presence Server
Cisco Tandeberg Telepresence Video Communication Server (VCS)
Cisco Telepresence Multipoint Control Unit (MCU)
Cisco Telepresence Video Communication Server
Cisco Unity Connection
Web Server
Apache Web Server
Microsoft IIS for Windows 2000 and 2003
Microsoft IIS for Windows 2008
NGINX Web Server
Blade Servers
Cisco UCS Server
HP BladeSystem
Cloud Access Security Broker
Fortinet FortiCASB
Oracle Cloud Access Security Broker (CASB)
Cloud Applications
Alicide.io KAudit
AWS Access Key IAM Permissions and IAM Policies
AWS CloudTrail API
Amazon AWS EC2
AWS EC2 CloudWatch API
AWS Elastic Load Balancer
AWS Kinesis
AWS RDS
AWS Security Hub
AWS Simple Queue Service (SQS)
Amazon Simple Storage Service (AWS S3)
Box.com
Cisco Umbrella
Google Cloud Platform - Pub/Sub Integration
Google Workspace (Formerly G Suite and Google Apps)
Microsoft Azure Audit
Microsoft Office365 Audit
Microsoft Cloud App Security
Microsoft Defender for Identity/Microsoft Azure ATP
Microsoft Azure Compute
Microsoft Azure Event Hub
Okta
Adding Users from Okta
Configuring Okta Authentication
Logging In to Okta
Setting Up External Authentication
Oracle Cloud Infrastructure
Salesforce CRM Audit
Zscaler Nanolog Streaming Service (NSS)
Console Access Devices
Lantronix SLC Console Manager
End Point Security Software
Bit9 Security Platform
Carbon Black Security Platform
Cisco AMP Cloud V0
Cisco AMP Cloud V1
Cisco Security Agent (CSA)
CloudPassage Halo
Crowdstrike
Cybereason
Digital Guardian CodeGreen DLP
ESET NOD32 Anti-Virus
FortiClient
Fortinet FortiEDR
Malwarebytes Breach Remediation
MalwareBytes EndPoint Protection
McAfee ePolicy Orchestrator (ePO)
Microsoft Windows Defender ATP
MobileIron Sentry and Connector
Netwrix Auditor (via Correlog Windows Agent)
Palo Alto Traps Endpoint Security Manager
SentinelOne
Sophos Central
Sophos Endpoint Security and Control
Symantec Endpoint Protection
Symantec SEPM
Tanium Connect
Trend Micro Interscan Web Filter
Trend Micro Intrusion Defense Firewall (IDF)
Trend Micro OfficeScan
Firewalls
Check Point FireWall-1
Check Point Provider-1 Firewall
Configuring MDS for Check Point Provider-1 Firewalls
Configuring MLM for Check Point Provider-1 Firewalls
Configuring CMA for Check Point Provider-1 Firewalls
Configuring CLM for Check Point Provider-1 Firewalls
Check Point VSX Firewall
Cisco Adaptive Security Appliance (ASA)
Cisco Firepower Threat Defense (FTD)
Clavister Firewall
Cyberoam Firewall
Dell SonicWALL Firewall
Fortinet FortiGate Firewall
Hillstone Firewall
Imperva Securesphere Web App Firewall
Juniper Networks SSG Firewall
McAfee Firewall Enterprise (Sidewinder)
Palo Alto Firewall
Sophos UTM Firewall
Stormshield Network Security
Tigera Calico
UserGate UTM Firewall
WatchGuard Firebox Firewall
Load Balancers and Application Firewalls
Barracuda Web Application Firewall
Brocade ServerIron ADX
Citrix Netscaler Application Delivery Controller (ADC)
F5 Networks Application Security Manager
F5 Networks Local Traffic Manager
F5 Networks Web Accelerator
Fortinet FortiADC
Qualys Web Application Firewall
Zscaler Cloud Firewall
Log Aggregators
Fortinet FortiAnalyzer
Network Compliance Management Applications
Cisco Network Compliance Manager
PacketFence Network Access Control (NAC) Integration
Network Detection and Response (NDR)
Fortinet FortiNDR (Formerly FortiAI)
Zeek Network Security Monitor (Previously known as Bro)
Network Intrusion Detection System
Microsoft Advanced Threat Analytics (ATA) On Premise Platform
Zeek Network Security Monitor (Previously known as Bro)
Network Intrusion Prevention Systems (IPS)
3COM TippingPoint UnityOne IPS
AirTight Networks SpectraGuard
Alert Logic IRIS API
Armis Asset Intelligence Platform
Cisco FireSIGHT and FirePower Threat Defense
Cisco Intrusion Protection System
Cisco Stealthwatch
Claroty Continuous Threat Detection
Corero Smartwall Threat Defense System
Cylance Protect Endpoint Protection
Cyphort Cortext Endpoint Protection
Damballa Failsafe
Darktrace CyberIntelligence Platform
Dragos Platform
FireEye Malware Protection System (MPS)
FortiDDoS
Fortinet FortiDeceptor
Fortinet FortiNAC
Fortinet FortiSandbox
Fortinet FortiTester
IBM Internet Security Series Proventia
Juniper DDoS Secure
Juniper Networks IDP Series
McAfee IntruShield
McAfee Stonesoft IPS
Motorola AirDefense
Nozomi
Palo Alto Cortex XDR
Radware DefensePro
Snort Intrusion Prevention System
Sourcefire 3D and Defense Center
Trend Micro Deep Discovery
Zeek (Bro) installed on Security Onion
Operational Technology
APC Netbotz Environmental Monitor
APC UPS
Claroty Continuous Threat Detection
Dragos Platform
Generic UPS
Hirschman SCADA Firewalls and Switches
Liebert FPC
Liebert HVAC
Liebert UPS
Microsoft Defender for IoT (Was CyberX OT/IoT Security)
Nozomi Central Management Control
Nozomi SCADAguardian
OTORIO RAM2 (Risk Assessment, Monitoring and Management)
Routers and Switches
Alcatel TiMOS and AOS Switch
Arista Router and Switch
ArubaOS-CX Switching Platform
Brocade NetIron CER Routers
Cisco 300 Series Routers
Cisco IOS Router and Switch
How CPU and Memory Utilization is Collected for Cisco IOS
Cisco Meraki Cloud Controller and Network Devices
Cisco NX-OS Router and Switch
Cisco ONS
Cisco Viptela SDWAN Router
Dell Force10 Router and Switch
Dell NSeries Switch
Dell PowerConnect Switch and Router
Foundry Networks IronWare Router and Switch
HP/3Com ComWare Switch
HP ProCurve Switch
HP Value Series (19xx) and HP 3Com (29xx) Switch
Hirschman SCADA Firewalls and Switches
Juniper Networks JunOS Switch
Mikrotek Router
Nortel ERS and Passport Switch
Security Gateways
Barracuda Networks Spam Firewall
Blue Coat Web Proxy
Cisco IronPort Mail Gateway
Cisco IronPort Web Gateway
Fortinet FortiMail
Fortinet FortiProxy
Fortinet FortiWeb
Imperva Securesphere DB Monitoring Gateway
Imperva Securesphere Security Gateway
McAfee Vormetric Data Security Manager
McAfee Web Gateway
Microsoft ISA Server
Proofpoint
Squid Web Proxy
SSH Comm Security CryptoAuditor
Websense Web Filter
Security Information and Event Management
SAP Enterprise Threat Detection (ETD)
Security Orchestration (SOAR)
Fortinet FortiSOAR
Servers and Workstations
Apple MacOS Server
HP UX Server
IBM AIX Server
IBM OS400 Server
Linux Server
Microsoft Windows Server
QNAP Turbo NAS
Sun Solaris Server
Storage
Brocade SAN Switch
Dell Compellant Storage
Dell EqualLogic Storage
EMC Clarion Storage
EMC Isilon Storage
EMC VNX Storage
NetApp DataOnTap
NetApp Filer Storage
Nimble Storage
Nutanix Storage
Threat Intelligence
FortiInsight
Fortinet FortiNDR (Formerly FortiAI)
Lastline
ThreatConnect
Virtualization
HyperV
HyTrust CloudControl
KVM
Nutanix Prism
VMware ESX
VPN Gateways
Cisco VPN 3000 Gateway
Cyxtera AppGuard
Juniper Networks SSL VPN Gateway
Microsoft PPTP VPN Gateway
Pulse Secure
Vulnerability Scanners
AlertLogic
Digital Defense Frontline Vulnerability Manager
Green League WVSS
McAfee Foundstone Vulnerability Scanner
Qualys QualysGuard Scanner
Qualys Vulnerability Scanner
Rapid7 NeXpose Vulnerability Scanner (Vulnerability Management On-Premises)
Rapid7 InsightVM (Platform Based Vulnerability Management)
Tenable.io
Tenable Nessus Vulnerability Scanner
Tenable Security Center
YXLink Vulnerability Scanner
WAN Accelerators
Cisco Wide Area Application Server
Riverbed SteelHead WAN Accelerator
Wireless LANs
Aruba Networks Wireless LAN
Cisco Wireless LAN
CradlePoint
FortiAP
FortiWLC
Motorola WiNG WLAN AP
Ruckus Wireless LAN
Ubiquiti
Using Virtual IPs to Access Devices in Clustered Environments
Syslog over TLS
SNMP V3 Traps
Flow Support
Appendix
Access Credentials
Ingesting JSON Formatted Events Received via HTTP(S) POST
Home
FortiSIEM 6.5.0
External Systems Configuration Guide
6.5.0
7.2.4
7.2.3
7.2.2
7.2.1
7.2.0
7.1.7
7.1.6
7.1.5
7.1.4
7.1.3
7.1.2
7.1.1
7.1.0
7.0.3
7.0.2
7.0.1
7.0.0
6.7.9
6.7.8
6.7.7
6.7.6
6.7.5
6.7.4
6.7.3
6.7.2
6.7.1
6.7.0
6.6.5
6.6.4
6.6.3
6.6.2
6.6.1
6.6.0
6.5.3
6.5.2
6.5.1
6.5.0
6.4.4
6.4.3
6.4.2
6.4.1
6.4.0
6.3.3
6.3.2
6.3.1
6.3.0
6.2.1
6.2.0
6.1.2
6.1.1
6.1.0
5.4.0
5.3.3
5.3.2
5.3.1
5.3.0
5.0.0
Remote Desktop
Remote Desktop
FortiSIEM supports this remote desktop application for discovery and monitoring.
Citrix Receiver (ICA)
Previous
Next
Remote Desktop
Remote Desktop
FortiSIEM supports this remote desktop application for discovery and monitoring.
Citrix Receiver (ICA)
Previous
Next
Home
Product Pillars
Network Security
Network Security
FortiGate / FortiOS
FortiGate 5000
FortiGate 6000
FortiGate 7000
FortiProxy
NOC & SOC Management
FortiManager
FortiManager Cloud
FortiAnalyzer
FortiAnalyzer Cloud
FortiMonitor
FortiGate Cloud
Enterprise Networking
Secure SD-WAN
FortiLAN Cloud
FortiSwitch
FortiAP / FortiWiFi
FortiAP-U Series
FortiNAC-F
FortiExtender
FortiExtender Cloud
FortiAIOps
Business Communications
FortiFone
FortiVoice
FortiVoice Cloud
FortiRecorder
FortiCamera
Zero Trust Access
ZTNA
Zero Trust Network Access
FortiClient EMS
SASE
FortiSASE
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken Cloud
FortiToken
Cloud Security
Hybrid Cloud Security
FortiGate Public Cloud
FortiGate Private Cloud
FortiFlex
Cloud Native Protection
FortiCNP
FortiDevSec
Web Application / API Protection
FortiWeb
FortiWeb Cloud
FortiADC
FortiGSLB
FortiGuard ABP
SAAS Security
FortiMail
FortiMail Cloud
FortiCASB
Security Operations
SOC Platform
FortiAnalyzer
FortiAnalyzer Cloud
FortiSIEM
/
FortiSIEM Cloud
FortiSOAR
FortiPhish
Advanced Threat Protection
FortiSandbox
FortiSandbox Cloud
FortiNDR
FortiNDR Cloud
FortiDeceptor
FortiInsight
FortiInsight Cloud
FortiIsolator
Endpoint Security
FortiClient
FortiClient Cloud
FortiEDR
Best Practices
Solution Hubs
Cloud
FortiCloud
Public & Private Cloud
Popular Solutions
Secure SD-WAN
Zero Trust Network Access
Secure Access
Next Generation Firewall
Security Fabric
Tele-Working
Multi-Factor Authentication
FortiASIC
Operational Technology
MSSP
4-D Resources
Secure SD-WAN
Zero Trust Network Access
Wireless
Switching
Secure Access Service Edge
Identity and Access Management
Next Generation Firewall
Hardware Guides
FortiAnalyzer
FortiAnalyzer Big-Data
FortiADC
FortiAP / FortiWiFi
FortiAP U-Series
FortiAuthenticator
FortiCache
FortiCarrier
FortiController
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiExtender
FortiGate
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiHypervisor
FortiIsolator
FortiMail
FortiManager
FortiNAC
FortiNDR
FortiProxy
FortiRecorder
FortiRPS
FortiSandbox
FortiSIEM
FortiSwitch
FortiTester
FortiToken
FortiVoice
FortiWAN
FortiWeb
FortiWLC
FortiWLM
Product A-Z
AscenLink
AV Engine
AWS Firewall Rules
Container FortiOS
FortiADC
FortiADC E Series
FortiADC Manager
FortiADC Private Cloud
FortiADC Public Cloud
FortiAIOps
FortiAnalyzer
FortiAnalyzer BigData
FortiAnalyzer BigData Private Cloud
FortiAnalyzer Cloud
FortiAnalyzer Private Cloud
FortiAnalyzer Public Cloud
FortiAP / FortiWiFi
FortiAP-U Series
FortiAuthenticator
FortiAuthenticator Private Cloud
FortiAuthenticator Public Cloud
FortiAuthProxy
FortiBalancer
FortiBranchSASE
FortiBridge
FortiCache
FortiCamera
FortiCamera Cloud
FortiCare Elite
FortiCarrier
FortiCASB
FortiCentral
FortiClient
FortiClient Cloud
FortiCloud Services
FortiCNP
FortiConnect
FortiController
FortiConverter Service
FortiConverter Tool
FortiCore
FortiCSPM
FortiCWP
FortiDAST
FortiDB
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiDeceptor DaaS
FortiDeceptor Private Cloud
FortiDeceptor Public Cloud
FortiDevSec
FortiDLP
FortiDLP Agent
FortiDLP Policies
FortiDNS
FortiEdge Cloud
FortiEDR/XDR
FortiEndpoint
FortiExplorer
FortiExplorer Go
FortiExtender
FortiFlex
FortiFone
FortiGate / FortiOS
FortiGate Cloud
FortiGate CNF
FortiGate Private Cloud
FortiGate Public Cloud
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiGate-as-a-Service
FortiGSLB
FortiGuard Advanced Bot Protection
FortiGuest
FortiHypervisor
FortiInsight
FortiInsight Cloud
FortiIPAM
FortiIsolator
FortiIsolator Public Cloud
FortiLAN Cloud
FortiMail
FortiMail Cloud
FortiManager
FortiManager Cloud
FortiManager Private Cloud
FortiManager Public Cloud
FortiMonitor
FortiNAC
FortiNAC-F
FortiNDR
FortiNDR (on-premise) Private Cloud
FortiNDR (on-premise) Public Cloud
FortiNDR Cloud
FortiNDR Cloud Sensors
FortiPAM
FortiPAM Private Cloud
FortiPAM Public Cloud
FortiPhish
FortiPlanner
FortiPolicy
FortiPortal
FortiPortal Public Cloud
FortiPresence
FortiPresence VM
FortiProxy
FortiProxy Private Cloud
FortiProxy Public Cloud
FortiRecon
FortiRecorder
FortiRPS
FortiSandbox
FortiSandbox Cloud
FortiSandbox Private Cloud
FortiSandbox Public Cloud
FortiSASE
FortiScanner
FortiSIEM
FortiSIEM Cloud
FortiSOAR
FortiSOAR Cloud
FortiSRA
FortiSwitch
FortiSwitch Manager
FortiTap
FortiTester
FortiTester Private Cloud
FortiTester Public Cloud
FortiToken
FortiToken Cloud
FortiTrust Identity
FortiVoice
FortiVoice Cloud
FortiVoice Private Cloud
FortiVoice Public Cloud
FortiWAN
FortiWAN Controller
FortiWeb
FortiWeb Cloud
FortiWeb Manager Private Cloud
FortiWeb Manager Public Cloud
FortiWeb Private Cloud
FortiWeb Public Cloud
FortiWLM
FortiZTP
IPS Engine
Lacework FortiCNAPP
Managed FortiGate Service
Overlay-as-a-Service
Security Awareness and Training
SOCaaS
Wireless Controller
Ordering Guides
Download PDF
Table of Contents
FortiSIEM External Systems Configuration Guide Online
Change Log
TABLE OF CONTENTS
Overview
FortiSIEM Port Usage
Supported Devices and Applications by Vendor
Applications
Application Server
Apache Tomcat
IBM WebSphere
Microsoft ASP.NET
Oracle GlassFish Server
Oracle WebLogic
Redhat JBOSS
Authentication Server
Cisco Access Control Server (ACS)
Cisco Duo
Cisco Identity Solution Engine (ISE)
CyberArk Password Vault
Fortinet FortiAuthenticator
Juniper Networks Steel-Belted RADIUS
Microsoft Internet Authentication Server (IAS)
Microsoft Network Policy Server (RAS VPN)
OneIdentity Safeguard
Vasco DigiPass
Database Server
IBM DB2 Server
Microsoft SQL Server
MySQL Server
Oracle Database Server
DHCP and DNS Server
Infoblox DNS/DHCP
ISC BIND DNS
Linux DHCP
Microsoft DHCP (2003, 2008)
Microsoft DNS (2003, 2008)
Directory Server
Microsoft Active Directory
Document Management Server
Microsoft SharePoint
Healthcare IT
Epic EMR/EHR System
Mail Server
Microsoft Exchange
Management Server/Appliance
Cisco Application Centric Infrastructure (ACI)
FortiInsight
Fortinet FortiManager
HPE Integrated Lights-Out (iLO)
VMware NSX for vSphere
Remote Desktop
Citrix Receiver (ICA)
Source Code Control
GitHub
GitLab API
GitLab CLI
Unified Communication Server
Avaya Call Manager
Cisco Call Manager
Cisco Contact Center
Cisco Presence Server
Cisco Tandeberg Telepresence Video Communication Server (VCS)
Cisco Telepresence Multipoint Control Unit (MCU)
Cisco Telepresence Video Communication Server
Cisco Unity Connection
Web Server
Apache Web Server
Microsoft IIS for Windows 2000 and 2003
Microsoft IIS for Windows 2008
NGINX Web Server
Blade Servers
Cisco UCS Server
HP BladeSystem
Cloud Access Security Broker
Fortinet FortiCASB
Oracle Cloud Access Security Broker (CASB)
Cloud Applications
Alicide.io KAudit
AWS Access Key IAM Permissions and IAM Policies
AWS CloudTrail API
Amazon AWS EC2
AWS EC2 CloudWatch API
AWS Elastic Load Balancer
AWS Kinesis
AWS RDS
AWS Security Hub
AWS Simple Queue Service (SQS)
Amazon Simple Storage Service (AWS S3)
Box.com
Cisco Umbrella
Google Cloud Platform - Pub/Sub Integration
Google Workspace (Formerly G Suite and Google Apps)
Microsoft Azure Audit
Microsoft Office365 Audit
Microsoft Cloud App Security
Microsoft Defender for Identity/Microsoft Azure ATP
Microsoft Azure Compute
Microsoft Azure Event Hub
Okta
Adding Users from Okta
Configuring Okta Authentication
Logging In to Okta
Setting Up External Authentication
Oracle Cloud Infrastructure
Salesforce CRM Audit
Zscaler Nanolog Streaming Service (NSS)
Console Access Devices
Lantronix SLC Console Manager
End Point Security Software
Bit9 Security Platform
Carbon Black Security Platform
Cisco AMP Cloud V0
Cisco AMP Cloud V1
Cisco Security Agent (CSA)
CloudPassage Halo
Crowdstrike
Cybereason
Digital Guardian CodeGreen DLP
ESET NOD32 Anti-Virus
FortiClient
Fortinet FortiEDR
Malwarebytes Breach Remediation
MalwareBytes EndPoint Protection
McAfee ePolicy Orchestrator (ePO)
Microsoft Windows Defender ATP
MobileIron Sentry and Connector
Netwrix Auditor (via Correlog Windows Agent)
Palo Alto Traps Endpoint Security Manager
SentinelOne
Sophos Central
Sophos Endpoint Security and Control
Symantec Endpoint Protection
Symantec SEPM
Tanium Connect
Trend Micro Interscan Web Filter
Trend Micro Intrusion Defense Firewall (IDF)
Trend Micro OfficeScan
Firewalls
Check Point FireWall-1
Check Point Provider-1 Firewall
Configuring MDS for Check Point Provider-1 Firewalls
Configuring MLM for Check Point Provider-1 Firewalls
Configuring CMA for Check Point Provider-1 Firewalls
Configuring CLM for Check Point Provider-1 Firewalls
Check Point VSX Firewall
Cisco Adaptive Security Appliance (ASA)
Cisco Firepower Threat Defense (FTD)
Clavister Firewall
Cyberoam Firewall
Dell SonicWALL Firewall
Fortinet FortiGate Firewall
Hillstone Firewall
Imperva Securesphere Web App Firewall
Juniper Networks SSG Firewall
McAfee Firewall Enterprise (Sidewinder)
Palo Alto Firewall
Sophos UTM Firewall
Stormshield Network Security
Tigera Calico
UserGate UTM Firewall
WatchGuard Firebox Firewall
Load Balancers and Application Firewalls
Barracuda Web Application Firewall
Brocade ServerIron ADX
Citrix Netscaler Application Delivery Controller (ADC)
F5 Networks Application Security Manager
F5 Networks Local Traffic Manager
F5 Networks Web Accelerator
Fortinet FortiADC
Qualys Web Application Firewall
Zscaler Cloud Firewall
Log Aggregators
Fortinet FortiAnalyzer
Network Compliance Management Applications
Cisco Network Compliance Manager
PacketFence Network Access Control (NAC) Integration
Network Detection and Response (NDR)
Fortinet FortiNDR (Formerly FortiAI)
Zeek Network Security Monitor (Previously known as Bro)
Network Intrusion Detection System
Microsoft Advanced Threat Analytics (ATA) On Premise Platform
Zeek Network Security Monitor (Previously known as Bro)
Network Intrusion Prevention Systems (IPS)
3COM TippingPoint UnityOne IPS
AirTight Networks SpectraGuard
Alert Logic IRIS API
Armis Asset Intelligence Platform
Cisco FireSIGHT and FirePower Threat Defense
Cisco Intrusion Protection System
Cisco Stealthwatch
Claroty Continuous Threat Detection
Corero Smartwall Threat Defense System
Cylance Protect Endpoint Protection
Cyphort Cortext Endpoint Protection
Damballa Failsafe
Darktrace CyberIntelligence Platform
Dragos Platform
FireEye Malware Protection System (MPS)
FortiDDoS
Fortinet FortiDeceptor
Fortinet FortiNAC
Fortinet FortiSandbox
Fortinet FortiTester
IBM Internet Security Series Proventia
Juniper DDoS Secure
Juniper Networks IDP Series
McAfee IntruShield
McAfee Stonesoft IPS
Motorola AirDefense
Nozomi
Palo Alto Cortex XDR
Radware DefensePro
Snort Intrusion Prevention System
Sourcefire 3D and Defense Center
Trend Micro Deep Discovery
Zeek (Bro) installed on Security Onion
Operational Technology
APC Netbotz Environmental Monitor
APC UPS
Claroty Continuous Threat Detection
Dragos Platform
Generic UPS
Hirschman SCADA Firewalls and Switches
Liebert FPC
Liebert HVAC
Liebert UPS
Microsoft Defender for IoT (Was CyberX OT/IoT Security)
Nozomi Central Management Control
Nozomi SCADAguardian
OTORIO RAM2 (Risk Assessment, Monitoring and Management)
Routers and Switches
Alcatel TiMOS and AOS Switch
Arista Router and Switch
ArubaOS-CX Switching Platform
Brocade NetIron CER Routers
Cisco 300 Series Routers
Cisco IOS Router and Switch
How CPU and Memory Utilization is Collected for Cisco IOS
Cisco Meraki Cloud Controller and Network Devices
Cisco NX-OS Router and Switch
Cisco ONS
Cisco Viptela SDWAN Router
Dell Force10 Router and Switch
Dell NSeries Switch
Dell PowerConnect Switch and Router
Foundry Networks IronWare Router and Switch
HP/3Com ComWare Switch
HP ProCurve Switch
HP Value Series (19xx) and HP 3Com (29xx) Switch
Hirschman SCADA Firewalls and Switches
Juniper Networks JunOS Switch
Mikrotek Router
Nortel ERS and Passport Switch
Security Gateways
Barracuda Networks Spam Firewall
Blue Coat Web Proxy
Cisco IronPort Mail Gateway
Cisco IronPort Web Gateway
Fortinet FortiMail
Fortinet FortiProxy
Fortinet FortiWeb
Imperva Securesphere DB Monitoring Gateway
Imperva Securesphere Security Gateway
McAfee Vormetric Data Security Manager
McAfee Web Gateway
Microsoft ISA Server
Proofpoint
Squid Web Proxy
SSH Comm Security CryptoAuditor
Websense Web Filter
Security Information and Event Management
SAP Enterprise Threat Detection (ETD)
Security Orchestration (SOAR)
Fortinet FortiSOAR
Servers and Workstations
Apple MacOS Server
HP UX Server
IBM AIX Server
IBM OS400 Server
Linux Server
Microsoft Windows Server
QNAP Turbo NAS
Sun Solaris Server
Storage
Brocade SAN Switch
Dell Compellant Storage
Dell EqualLogic Storage
EMC Clarion Storage
EMC Isilon Storage
EMC VNX Storage
NetApp DataOnTap
NetApp Filer Storage
Nimble Storage
Nutanix Storage
Threat Intelligence
FortiInsight
Fortinet FortiNDR (Formerly FortiAI)
Lastline
ThreatConnect
Virtualization
HyperV
HyTrust CloudControl
KVM
Nutanix Prism
VMware ESX
VPN Gateways
Cisco VPN 3000 Gateway
Cyxtera AppGuard
Juniper Networks SSL VPN Gateway
Microsoft PPTP VPN Gateway
Pulse Secure
Vulnerability Scanners
AlertLogic
Digital Defense Frontline Vulnerability Manager
Green League WVSS
McAfee Foundstone Vulnerability Scanner
Qualys QualysGuard Scanner
Qualys Vulnerability Scanner
Rapid7 NeXpose Vulnerability Scanner (Vulnerability Management On-Premises)
Rapid7 InsightVM (Platform Based Vulnerability Management)
Tenable.io
Tenable Nessus Vulnerability Scanner
Tenable Security Center
YXLink Vulnerability Scanner
WAN Accelerators
Cisco Wide Area Application Server
Riverbed SteelHead WAN Accelerator
Wireless LANs
Aruba Networks Wireless LAN
Cisco Wireless LAN
CradlePoint
FortiAP
FortiWLC
Motorola WiNG WLAN AP
Ruckus Wireless LAN
Ubiquiti
Using Virtual IPs to Access Devices in Clustered Environments
Syslog over TLS
SNMP V3 Traps
Flow Support
Appendix
Access Credentials
Ingesting JSON Formatted Events Received via HTTP(S) POST