Fortinet white logo
Fortinet white logo

User Guide

Setting Collectors (Enterprise)

Complete these steps to add a Collector:

  1. Go to ADMIN > Setup > Collector tab.
  2. Click New.
  3. In the Event Collector Definition dialog box, enter the information below.
    SettingsGuidelines
    Name[Required] Collector name
    Guaranteed EPS[Required] Events from this Collector are always accepted when its event rate is below this Guaranteed EPS. FortiSIEM will re-allocate excess EPS (license minus the sum of Guaranteed EPS over all the collectors) based on need but the allocation will never go below the Guaranteed EPS.
    Upload Rate Limit (Kbps)Maximum rate limit (in Kbps) at which a Collector can send events to all Workers. Rate limit is enforced at periodic 3 minute intervals. When either the upload rate limit or EPS limit are hit, events are buffered at the Collector and sent later.
    Upload EPS Limit Maximum events per second at which a Collector can send events to all Workers. EPS limit is enforced at periodic 3 minute intervals. When either the upload rate limit or EPS limit are hit, events are buffered at the Collector and sent later.
    Start Time[Required] Select a specific start date or check 'Unlimited'. Collectors will not work outside of start and end dates if specific dates are chosen.
    End Time[Required] Select a specific end date or check 'Unlimited'. Collectors will not work outside of start and end dates if specific dates are chosen.
    Event WorkerWorker list that Collector uploads event files to.
  4. Click Save.

Installing a Collector

For installing Collectors, see the "Install Collector" sections in the specific Installation Guides. See also the Upgrade and Sizing Guides available in the FortiSIEM Documents Library here.

Registering a Collector

Once a Collector has been created in the GUI, the Collector needs to be installed and registered.

For registering a Collector, follow these steps:

  1. SSH to the Collector.
  2. Run the following command:

    phProvisionCollector --add <user> '<password>' <super IP or host> <organization> <collectorName>

    The password should be enclosed in single quotes to ensure that any non-alphanumeric characters are escaped. In Enterprise mode, use super as the organization .

    Refer to the tables in steps 3 and 4 here for more information about these settings: <user>, <password>, <organization> and <collectorName>

Setting Collectors (Enterprise)

Complete these steps to add a Collector:

  1. Go to ADMIN > Setup > Collector tab.
  2. Click New.
  3. In the Event Collector Definition dialog box, enter the information below.
    SettingsGuidelines
    Name[Required] Collector name
    Guaranteed EPS[Required] Events from this Collector are always accepted when its event rate is below this Guaranteed EPS. FortiSIEM will re-allocate excess EPS (license minus the sum of Guaranteed EPS over all the collectors) based on need but the allocation will never go below the Guaranteed EPS.
    Upload Rate Limit (Kbps)Maximum rate limit (in Kbps) at which a Collector can send events to all Workers. Rate limit is enforced at periodic 3 minute intervals. When either the upload rate limit or EPS limit are hit, events are buffered at the Collector and sent later.
    Upload EPS Limit Maximum events per second at which a Collector can send events to all Workers. EPS limit is enforced at periodic 3 minute intervals. When either the upload rate limit or EPS limit are hit, events are buffered at the Collector and sent later.
    Start Time[Required] Select a specific start date or check 'Unlimited'. Collectors will not work outside of start and end dates if specific dates are chosen.
    End Time[Required] Select a specific end date or check 'Unlimited'. Collectors will not work outside of start and end dates if specific dates are chosen.
    Event WorkerWorker list that Collector uploads event files to.
  4. Click Save.

Installing a Collector

For installing Collectors, see the "Install Collector" sections in the specific Installation Guides. See also the Upgrade and Sizing Guides available in the FortiSIEM Documents Library here.

Registering a Collector

Once a Collector has been created in the GUI, the Collector needs to be installed and registered.

For registering a Collector, follow these steps:

  1. SSH to the Collector.
  2. Run the following command:

    phProvisionCollector --add <user> '<password>' <super IP or host> <organization> <collectorName>

    The password should be enclosed in single quotes to ensure that any non-alphanumeric characters are escaped. In Enterprise mode, use super as the organization .

    Refer to the tables in steps 3 and 4 here for more information about these settings: <user>, <password>, <organization> and <collectorName>