Fortinet black logo

FortiSIEM Reference Architecture Using ClickHouse

Monitoring Network Devices

Monitoring Network Devices

Network device monitoring is typically performed by:

  • SNMP for performance and availability monitoring

  • SSH for configuration monitoring

  • Syslog for device log monitoring

  • Some devices also have platform specific integration via API or similar

Choose the device monitoring method(s) based on the device monitoring use-case, for example:

  • Use syslog alone for basic log ingestion

  • Add SNMP for performance monitoring

  • Add SSH for configuration monitoring

Performing an SNMP discovery of network devices is generally recommended, as it results in the CMDB being populated with device information, performance monitors being enabled, and the FortiSIEM analyst benefiting from additional context and information.

Consult the FortiSIEM External Systems Configuration Guide at https://docs.fortinet.com/document/fortisiem/7.1.0/external-systems-configuration-guide/780675/fortisiem-external-systems-configuration-guide-online for supported devices and the specific protocols required to monitor them.

Monitoring Network Devices

Network device monitoring is typically performed by:

  • SNMP for performance and availability monitoring

  • SSH for configuration monitoring

  • Syslog for device log monitoring

  • Some devices also have platform specific integration via API or similar

Choose the device monitoring method(s) based on the device monitoring use-case, for example:

  • Use syslog alone for basic log ingestion

  • Add SNMP for performance monitoring

  • Add SSH for configuration monitoring

Performing an SNMP discovery of network devices is generally recommended, as it results in the CMDB being populated with device information, performance monitors being enabled, and the FortiSIEM analyst benefiting from additional context and information.

Consult the FortiSIEM External Systems Configuration Guide at https://docs.fortinet.com/document/fortisiem/7.1.0/external-systems-configuration-guide/780675/fortisiem-external-systems-configuration-guide-online for supported devices and the specific protocols required to monitor them.