May 4, 2022, 1:27 p.m. | /u/BCSecA

cybersecurity www.reddit.com

Hello Everyone,

I have FortiAnalyzer setup to forward logs via Syslog into Azure Sentinel.

Works fantastically but I am noticing that the FortiAnalyzer is forwarding a lot of "useless" information as well. For a smaller organization we are ingesting a little over 16gb of logs per day purely from the FortiAnalyzer.

I was hoping that someone would have a similar setup and would be willing to share any filters or exclusions they are using on the Log Forwarding configuration in …

azure cybersecurity fortianalyzer forwarding log sentinel

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Cloud Technical Solutions Engineer, Security

@ Google | Mexico City, CDMX, Mexico

Assoc Eng Equipment Engineering

@ GlobalFoundries | SGP - Woodlands

Staff Security Engineer, Cloud Infrastructure

@ Flexport | Bellevue, WA; San Francisco, CA

Software Engineer III, Google Cloud Security and Privacy

@ Google | Sunnyvale, CA, USA

Software Engineering Manager II, Infrastructure, Google Cloud Security and Privacy

@ Google | San Francisco, CA, USA; Sunnyvale, CA, USA