Fortinet FortiAnalyzer
Connect Fortinet FortiAnalyzer to Radiant Security to forward aggregated FortiGate firewall and threat syslog for AI triage.
Fortinet FortiAnalyzer is a log aggregation and analytics platform that centralizes logs from FortiGate firewalls and other Fortinet devices across a customer environment. Connecting FortiAnalyzer forwards aggregated FortiGate firewall and threat syslog to Radiant Security in a single stream, with optional device-level filtering applied at the FortiAnalyzer. Radiant uses the syslog data to triage firewall and threat alerts in context, giving analysts faster verdicts on whether observed traffic reflects a real compromise or routine network activity.
A FortiAnalyzer license is required to forward logs from FortiAnalyzer. To forward logs directly from FortiGate firewalls without FortiAnalyzer, refer to Fortinet FortiGate.
FortiAnalyzer can forward logs to Radiant Security in two ways:
Through the Radiant Agent (recommended). Forward to a Radiant Agent deployed in your environment.
Direct to Radiant Security. Forward over TLS to the Radiant syslog cluster. Use only when a Radiant Agent is not available.
Prerequisites
Add the data connector in Radiant Security
Log in to Radiant Security.
From the navigation menu, click Settings > Data Connectors, then click + Add Connector.
Search for and select Radiant Agent, then click Data Feeds.
Under Select your data feeds, select Fortinet Fortigate v7, then click Credentials.
Under Credential Name, enter an identifiable name for the Radiant Agent integration (e.g.,
Radiant Agent integration). To reuse an existing Radiant Agent credential, select it from the drop-down menu.Click Add Connector.
Configure FortiAnalyzer log forwarding through the Radiant Agent
Before starting, confirm the IP address of the Radiant Agent and the port configured to receive FortiAnalyzer data. If you do not know the port, contact your Customer Success representative. For Fortinet's reference, see Log forwarding.
Log in to the FortiAnalyzer Console.
Go to System Settings > Log Forwarding.
On the toolbar, click Create New.
Configure the following settings:
Name:
RadiantSecurity_ConnectorStatus: ON
Remote Server Type: Syslog
Server FQDN/IP: the IP address of the Radiant Agent
Syslog Server Port: the port configured on the Radiant Agent to receive FortiAnalyzer data
Reliable Connection: ON
(Optional) Under Device Filters, select the FortiGate devices whose logs should be forwarded to Radiant. If no devices are selected, logs from every connected FortiGate are forwarded.
Set Log Filters to ON, set Log messages that match to Any of the Following Conditions, then add these filters:
Log Type Equal To Traffic
Log Type Equal To Event
Log Type Equal To UTM

Click OK to save your changes.
Configure FortiAnalyzer log forwarding directly to Radiant Security
Use this path only when a Radiant Agent is not available. For Fortinet's reference, see Log forwarding.
Log in to the FortiAnalyzer Console.
Go to System Settings > Log Forwarding.
On the toolbar, click Create New.
Configure the following settings:
Name:
RadiantSecurity_ConnectorStatus: ON
Remote Server Type: Syslog
Server FQDN/IP:
cluster.syslog.radiantsecurity.aiSyslog Server Port:
6514Reliable Connection: ON
(Optional) Under Device Filters, select the FortiGate devices whose logs should be forwarded to Radiant. If no devices are selected, logs from every connected FortiGate are forwarded.
Set Log Filters to ON, set Log messages that match to Any of the Following Conditions, then add these filters:
Log Type Equal To Traffic
Log Type Equal To Event
Log Type Equal To UTM
Click OK to save your changes.
Verify ingestion
After FortiAnalyzer begins forwarding, confirm alerts and events are reaching Radiant.
In Radiant, navigate to Log Management.
Filter by
rs_connectorType:"fortigate".Confirm recent alerts and events appear.
Allow several minutes for alerts and events to be parsed, indexed, and available for search.
Last updated
Was this helpful?