QNAP Turbo NAS
Support Added: FortiSIEM 4.7.2
Vendor Version Tested: Not Provided
Vendor: QNAP
Product Information: https://www.qnap.com/en-us
What is Discovered and Monitored
Protocol | Information Discovered | Metrics Collected | Used For |
---|---|---|---|
Syslog |
|
General logs including events and access. |
Security Monitoring |
Event Types
In Admin > Device Support > Event Types, search for "qnap" to see the event types associated with this device.
Reports
The following report is available for QNAP.
-
QNAP Turbo NAS File Access - Reports All Turbo NAS File Accesses (syslog)
Configuration
Syslog
For syslog, configure QNAP Turbo NAS by accessing QuLog Center and taking the following steps.
References:
-
https://www.qnap.com/en/how-to/faq/article/what-kind-of-syslog-format-can-qnap-nas-receive-and-send#
-
Navigate to QuLog Service > Log Sender > Send to Syslog Server.
-
Toggle Send logs to remote syslog server on.
-
Click Add Destination, and take the following steps.
-
In the Destination IP field, enter the FortiSIEM Supervisor IP address.
-
In the Port field, enter "514".
-
In the Transfer protocol field, select TLS.
-
For Log type, select the type(s), for example Event & Access Logs.
-
For Format, select RFC-3164.
-
When done, click Apply.
-
-
Proceed to Setup in FortiSIEM.
Setup in FortiSIEM
Complete these steps in the FortiSIEM UI:
- Go to the ADMIN > Setup > Credentials tab.
- In Step 1: Enter Credentials, click New to create a new credential.
- Follow the instructions in "Setting Credentials" in the User's Guide to create a new credential.
- Enter these settings in the Access Method Definition dialog box:
Setting Value Name <set name> Device Type QNAP Turbo NAS Access Protocol See Access Credentials Port See Access Credentials Password config See Password Configuration
- In Step 2: Enter IP Range to Credential Associations, click New to create a new mapping.
- Enter a host name, an IP, or an IP range in the IP/Host Name field.
- Select the name of your credential in step 2 from the Credentials drop-down list.
- Click Save.
- Click the Test drop-down list and select Test Connectivity to test the connection to QNAP Turbo NAS.
- To see the jobs associated with QNAP, select ADMIN > Setup > Pull Events.
- To see the received events select ANALYTICS, then enter "QNAP" in the search box.
Sample Logs
<30>Jun 25 14:41:36 Galaxy qlogd[8029]: conn log: Users: EXAMPLE\exampleuser123, Source IP: 192.0.20.0, Computer name: 192.0.20.0, Connection type: SAMBA, Accessed resources: STORE/AA Doe - MPLS Project/desktop.ini, Action: Read
<38>Jun 25 14:42:17 Galaxy qlogd[8029]: conn log: Users: admin, Source IP: 192.0.20.0, Computer name: ---, Connection type: HTTP, Accessed resources: Administration, Action: Login OK