Flow Support
FortiSIEM supports NetFlow v5, NetFlow v9, IPFIX, sFlow, and JFlow. You need to configure any device to send traffic to FortiSIEM on these ports and FortiSIEM will automatically parse and handle the flows. No other configuration is required.
Flow traffic should be sent to the below specified ports.
Protocol / Port |
Network Flow |
Supported Versions |
---|---|---|
UDP / 2055 | NetFlow | v5, v9 |
UDP / 2055 | Internet Protocol Flow Information Export (IPFIX) | v10 |
UDP / 6343 | sFlow | v5 |
UDP / 6343 |
JFlow |
v5 |
If you want to send to another port, then you need to configure port translation NAT on FortiSIEM.
Netflow IPv4 and IPv6
FortiSIEM supports receiving netflow for both IPv4 and IPv6 and parsing of IP addresses.