Support Added: FortiSIEM 5.2.5
Last Modification: FortiSIEM 6.5.0
Vendor Version Tested: Not Provided
Vendor: Nozomi Networks
Product: Nozomi Networks SCADAguardian
Product Information: https://www.nozominetworks.com/products/guardian/
- What is Discovered and Monitored
- Event Types
- Configuring Syslog on Nozomi
- Configuring FortiSIEM for Nozomi
What is Discovered and Monitored
|Protocol||Information discovered||Metrics collected||Used for|
|Syslog||Device type||Node detection, protocol information, network changes||Security and Compliance|
In ADMIN > Device Support > Event Types, search for "Nozomi" to see the event types associated with this device.
There are no specific rules for Nozomi, however rules that match the Event Type Groups associated with Nozomi Events may trigger.
There are no specific Reports for Nozomi, however reports that match the Event Type Groups associated with Nozomi Events may return results.
Configuring Syslog on Nozomi
- Log in to the Guardian console.
- Navigate to Administration->Data Integration.
- Press +Add on the right side of the screen.
- Select the Common Event Format (CEF) from the drop down.
- You should see the data entry screen.
- Enter the appropriate host information. For example
- Select Enable sending Alerts and/or Enable sending Audit Logs and/or Enable sending Health Logs.
- Press New Endpoint.
Configuring FortiSIEM for Nozomi
Complete these steps in the FortiSIEM UI:
- Go to the ADMIN > Setup > Credentials tab.
- In Step 1: Enter Credentials, click New to create a new credential.
- Follow the instructions in "Setting Credentials" in the User's Guide to create a new credential.
- Enter these settings in the Access Method Definition dialog box and click Save:
Settings Description Name Enter a name for the credential Device Type Nozomi Networks SCADAGuardian Access Protocol Nozomi REST API User Name Enter the username used to access your Nozomi server. Password Enter the password associated with your username. Description Description of the device.
- In Step 2: Enter IP Range to Credential Associations, click New to create a mapping.
- Enter a host name, an IP, or an IP range in the IP/Host Name field.
- Select the name of your Nozomi credential from the Credentials drop-down list.
- Click Save.
- Click the Test drop-down list and select Test Connectivity to test the connection to the Nozomi server.
- Navigate to ADMIN > Setup > Discovery.
- Click New to create a Nozomi scan discovery definition.
- In the Discovery Definition dialog box, take the following steps:
- In the Name field, enter a name for the Discovery Definition.
- From the Discovery Type drop-down list, select Nozomi Scan.
- In the Credential drop-down list, your Nozomi Access Method Definition should be automatically selected.
- Fill in the other fields as necessary.
- When done, click Save.