FortiGate

Supported OS Linux Windows Mac OS

marketplace

Overview

  • FortiGate provides a full range of threat protection capabilities, including firewall, intrusion prevention, antivirus, SSL inspection, and application control. FortiGate reduces complexity with automated visibility into applications, users, and networks, and provides security ratings to adopt security best practices.

    This integration collects the following log types and subtypes:

    TypeDescriptionSubType
    TrafficRecords traffic flow information such as an HTTP/HTTPS request and its response, if anyFORWARD, LOCAL
    EventRecords system and administrative eventsSYSTEM, USER, VPN, WIRELESS
    UTMRecords UTM EventsIPS, WEB

NOTE: Support for the metric has been discontinued and its related panels are now deprecated in integration v1.1.0 and above. We plan to completely remove the same in upcoming releases of the integration.

This integration includes the following Datadog Cloud SIEM detection rules for enhanced monitoring and security:

  1. FortiGate detected access to malicious or risky websites
  2. FortiGate activity detected from new or suspicious location
  3. FortiGate detected rogue access point
  4. Received FortiGate event with critical severity
  5. FortiGate observed frequent large amounts of data transferred to file-sharing sites
  6. FortiGate detected high number of blocked actions
  7. FortiGate observed multiple authentication failures
  8. FortiGate received multiple intrusion prevention events from a single source
  9. FortiGate observed unusual network traffic

Note: To use the out-of-the-box detection rules, the relevant integration must be installed in Datadog, and Cloud SIEM must be enabled.

Support

For support or feature requests, contact Crest Data through the following channels:


This application is made available through the Datadog Marketplace and is supported by a Datadog Technology Partner. To use it, purchase this application in the Marketplace.

PREVIEWING: drodriguezhdez/add_public_docs_log_summarization