Fortinet white logo
Fortinet white logo

External Systems Configuration Guide

QNAP Turbo NAS

QNAP Turbo NAS

Support Added: FortiSIEM 4.7.2

Vendor Version Tested: Not Provided

Vendor: QNAP

Product Information: https://www.qnap.com/en-us

What is Discovered and Monitored

Protocol Information Discovered Metrics Collected Used For

Syslog

General logs including events and access.

Security Monitoring

Event Types

In Admin > Device Support > Event Types, search for "qnap" to see the event types associated with this device.

Reports

The following report is available for QNAP.

  • QNAP Turbo NAS File Access - Reports All Turbo NAS File Accesses (syslog)

Configuration

Syslog

For syslog, configure QNAP Turbo NAS by accessing QuLog Center and taking the following steps.

References:

  1. Navigate to QuLog Service > Log Sender > Send to Syslog Server.

  2. Toggle Send logs to remote syslog server on.

  3. Click Add Destination, and take the following steps.

    1. In the Destination IP field, enter the FortiSIEM Supervisor IP address.

    2. In the Port field, enter "514".

    3. In the Transfer protocol field, select TLS.

    4. For Log type, select the type(s), for example Event & Access Logs.

    5. For Format, select RFC-3164.

    6. When done, click Apply.

  4. Proceed to Setup in FortiSIEM.

Setup in FortiSIEM

Complete these steps in the FortiSIEM UI:

  1. Go to the ADMIN > Setup > Credentials tab.
  2. In Step 1: Enter Credentials, click New to create a new credential.
    1. Follow the instructions in "Setting Credentials" in the User's Guide to create a new credential.
    2. Enter these settings in the Access Method Definition dialog box:

      SettingValue
      Name<set name>
      Device TypeQNAP Turbo NAS
      Access ProtocolSee Access Credentials
      PortSee Access Credentials
      Password configSee Password Configuration
  3. In Step 2: Enter IP Range to Credential Associations, click New to create a new mapping.
    1. Enter a host name, an IP, or an IP range in the IP/Host Name field.
    2. Select the name of your credential in step 2 from the Credentials drop-down list.
    3. Click Save.
  4. Click the Test drop-down list and select Test Connectivity to test the connection to QNAP Turbo NAS.
  5. To see the jobs associated with QNAP, select ADMIN > Setup > Pull Events.
  6. To see the received events select ANALYTICS, then enter "QNAP" in the search box.

Sample Logs

<30>Jun 25 14:41:36 Galaxy qlogd[8029]: conn log: Users: EXAMPLE\exampleuser123, Source IP: 192.0.20.0, Computer name: 192.0.20.0, Connection type: SAMBA, Accessed resources: STORE/AA Doe - MPLS Project/desktop.ini, Action: Read
<38>Jun 25 14:42:17 Galaxy qlogd[8029]: conn log: Users: admin, Source IP: 192.0.20.0, Computer name: ---, Connection type: HTTP, Accessed resources: Administration, Action: Login OK

QNAP Turbo NAS

QNAP Turbo NAS

Support Added: FortiSIEM 4.7.2

Vendor Version Tested: Not Provided

Vendor: QNAP

Product Information: https://www.qnap.com/en-us

What is Discovered and Monitored

Protocol Information Discovered Metrics Collected Used For

Syslog

General logs including events and access.

Security Monitoring

Event Types

In Admin > Device Support > Event Types, search for "qnap" to see the event types associated with this device.

Reports

The following report is available for QNAP.

  • QNAP Turbo NAS File Access - Reports All Turbo NAS File Accesses (syslog)

Configuration

Syslog

For syslog, configure QNAP Turbo NAS by accessing QuLog Center and taking the following steps.

References:

  1. Navigate to QuLog Service > Log Sender > Send to Syslog Server.

  2. Toggle Send logs to remote syslog server on.

  3. Click Add Destination, and take the following steps.

    1. In the Destination IP field, enter the FortiSIEM Supervisor IP address.

    2. In the Port field, enter "514".

    3. In the Transfer protocol field, select TLS.

    4. For Log type, select the type(s), for example Event & Access Logs.

    5. For Format, select RFC-3164.

    6. When done, click Apply.

  4. Proceed to Setup in FortiSIEM.

Setup in FortiSIEM

Complete these steps in the FortiSIEM UI:

  1. Go to the ADMIN > Setup > Credentials tab.
  2. In Step 1: Enter Credentials, click New to create a new credential.
    1. Follow the instructions in "Setting Credentials" in the User's Guide to create a new credential.
    2. Enter these settings in the Access Method Definition dialog box:

      SettingValue
      Name<set name>
      Device TypeQNAP Turbo NAS
      Access ProtocolSee Access Credentials
      PortSee Access Credentials
      Password configSee Password Configuration
  3. In Step 2: Enter IP Range to Credential Associations, click New to create a new mapping.
    1. Enter a host name, an IP, or an IP range in the IP/Host Name field.
    2. Select the name of your credential in step 2 from the Credentials drop-down list.
    3. Click Save.
  4. Click the Test drop-down list and select Test Connectivity to test the connection to QNAP Turbo NAS.
  5. To see the jobs associated with QNAP, select ADMIN > Setup > Pull Events.
  6. To see the received events select ANALYTICS, then enter "QNAP" in the search box.

Sample Logs

<30>Jun 25 14:41:36 Galaxy qlogd[8029]: conn log: Users: EXAMPLE\exampleuser123, Source IP: 192.0.20.0, Computer name: 192.0.20.0, Connection type: SAMBA, Accessed resources: STORE/AA Doe - MPLS Project/desktop.ini, Action: Read
<38>Jun 25 14:42:17 Galaxy qlogd[8029]: conn log: Users: admin, Source IP: 192.0.20.0, Computer name: ---, Connection type: HTTP, Accessed resources: Administration, Action: Login OK