Skip to main content

FortiSIEM Integration with SureMDM

To integrate FortiSIEM with the SureMDM Web Console, follow these steps:

  1. Navigate to SureMDM Web Console > Settings (icon located at the top-right of the screen) > Account Settings > SIEM Integration.
  2. Configure the following settings and click Validate.
SettingsDescription
Enable SIEM IntegrationEnable this option to allow configuration of SIEM settings.
Select ServerSelect FortiSIEM from the dropdown menu.
Syslog FormatSelect either RFC5424 or RFC3164, based on your FortiSIEM configuration.
Server AddressEnter the IP address or Fully Qualified Domain Name (FQDN) of the FortiSIEM server.
PortEnter the port number configured in FortiSIEM to receive syslog events.
ProtocolSelect the communication protocol (TCP, UDP, or TCP/TLS) configured in FortiSIEM.
TCP Message FramingSelect the TCP message framing option required by your FortiSIEM configuration. Otherwise, retain the default value (None).

After the configuration is successfully validated, SureMDM will automatically forward system activity logs and device logs to FortiSIEM using the configured syslog settings.

For additional information about the network ports required for FortiSIEM communication and external system integration, please refer to the FortiSIEM Port Usage Guide(Redirects to third party website)

Disclaimer

The third-party configuration steps in this article are based on the vendor's documentation available at the time of publication and may change. Always refer to the official vendor documentation for the latest instructions.

💬 Help us improve this documentation

Was this information useful?

Your feedback helps us keep our documentation accurate, up to date, and useful.