Fortinet black logo

User Guide

Forwarding FortiWeb attack logs to Threat Analytics

Copy Link
Copy Doc ID a9687b55-f2f2-11ee-8c42-fa163e15d75b:995708
Download PDF

Forwarding FortiWeb attack logs to Threat Analytics

Attack logs on FortiWeb can be forwarded to FortiWeb Cloud, which allows you to leverage the powerful AI-based Threat Analytics service that helps identify significant threats and zoom in on the threats that matter.

Prerequisites for using Threat Analytics for FortiWeb's attack logs:

  • You have a valid Threat Analytics service license.

  • Threat Analytics service is enabled in FortiWeb.

Please note that when your license expires or becomes invalid, the log forwarding will stop immediately regardless whether the Threat Analytics service is enabled.

To enable Threat Analytics:

  1. Contact Sales team to purchase a license with the Threat Analytics service, then register the license on Support site: HTTPs://support.fortinet.com
  2. Log in to FortiWeb.
  3. Check the status of Threat Analytics in the Licenses widget in Dashboard > Status. It should be displayed as Valid.
  4. In the System Information Widget in Dashboard > Status, click Enable Threat Analytics, then click OK in the pop-up window.
  5. Make sure Enable Attack Log is switched on in Log&Report > Log Config > Other Log Settings.
  6. Go to Dashboard > Status, click Add Widget, then select Threat Analytics in the System section. The Threat Analytics widget will be displayed on the Status page. You can view whether FortiWeb is successfully connected with FortiWeb Cloud and whether the attack logs are being forwarded.
  7. Wait for FortiWeb to generate attack logs.
  8. Log in to FortiWeb Cloud with the account you used when registering your license on Fortinet Support site.

Forwarding FortiWeb attack logs to Threat Analytics

Attack logs on FortiWeb can be forwarded to FortiWeb Cloud, which allows you to leverage the powerful AI-based Threat Analytics service that helps identify significant threats and zoom in on the threats that matter.

Prerequisites for using Threat Analytics for FortiWeb's attack logs:

  • You have a valid Threat Analytics service license.

  • Threat Analytics service is enabled in FortiWeb.

Please note that when your license expires or becomes invalid, the log forwarding will stop immediately regardless whether the Threat Analytics service is enabled.

To enable Threat Analytics:

  1. Contact Sales team to purchase a license with the Threat Analytics service, then register the license on Support site: HTTPs://support.fortinet.com
  2. Log in to FortiWeb.
  3. Check the status of Threat Analytics in the Licenses widget in Dashboard > Status. It should be displayed as Valid.
  4. In the System Information Widget in Dashboard > Status, click Enable Threat Analytics, then click OK in the pop-up window.
  5. Make sure Enable Attack Log is switched on in Log&Report > Log Config > Other Log Settings.
  6. Go to Dashboard > Status, click Add Widget, then select Threat Analytics in the System section. The Threat Analytics widget will be displayed on the Status page. You can view whether FortiWeb is successfully connected with FortiWeb Cloud and whether the attack logs are being forwarded.
  7. Wait for FortiWeb to generate attack logs.
  8. Log in to FortiWeb Cloud with the account you used when registering your license on Fortinet Support site.