Fortinet FortiWeb Firewall
The IBM QRadar SIEM DSM for Fortinet FortiWeb Firewall Gate parses events that are issued by Fortinet FortiWeb.
To integrate Fortinet FortiWeb Firewall with QRadar, complete the following steps:
- If automatic updates are not enabled, RPMs are available for download from the IBM® Support Website (http://www.ibm.com/support). Download and install the
most recent version of the following RPM on yourQRadar
Console:
FortinetFortiWeb DSM RPM - Configure your Fortinet FortiWeb Firewall server to send events to QRadar. For more information, see Configure Fortinet FortiWeb Firewall.
- If QRadar does not automatically detect the log source, add a Fortinet FortiWeb Firewall log source on the QRadar Console. For more information, see Syslog log source parameters for add Fortinet FortiWeb Firewall.