background image

Appliance Setup

Option

Description

--i6

IPv6-formatted address

--m6

IPv6 prefix

--g6

IPv6 gateway

-o

Installation option.

-z

Time zone. Possible values are

US/Pacific

,

Asia/Shanghai

,

Europe/London

, or

Africa/Tunis

--testpinghost

The URL used to test connectivity

Once the configuration is complete, the system reboots automatically.

Step 5: Register Collectors

Collectors can be deployed in Enterprise or Service Provider environments.

l

Enterprise Deployments

l

Service Provider Deployments

Enterprise Deployments

For enterprise deployments, follow these steps:

1.

Log in to Supervisor with

Admin

privileges.

2.

Go to

ADMIN > Settings > System > Event Worker

.

a.

Enter the IP of the Worker node. If a Supervisor node is only used, then enter the IP of the Supervisor node.
Multiple IP addresses can be entered on separate lines. In this case, the Collectors will load balance the upload
of events to the listed Event Workers.

Note

: Rather than using IP addresses, a DNS name is recommended. The reasoning is, should the IP

addressing change, it becomes a matter of updating the DNS rather than modifying the Event Worker IP
addresses in FortiSIEM.

b.

Click

OK

.

3.

Go to

ADMIN > Setup > Collectors

and add a Collector by entering:

a. Name

– Collector name.

b. Guaranteed EPS

– This is the EPS that the Collector will always be able to send. It could send more if there is

excess EPS available.

c. Start Time

and

End Time

– set to

Unlimited

.

4.

SSH to the Collector and run following script to register Collectors:

phProvisionCollector --add <

user

> '<

password

>' <

Super IP or Host

> <

Organization

>

<

CollectorName

>

The password should be enclosed in single quotes to ensure that any non-alphanumeric characters are escaped.

a.

Set

user

and

password

use the admin User Name and password for the Supervisor.

b.

Set

Super IP or Host

as the Supervisor's IP address.

c.

Set

Organization

. For Enterprise deployments, the default name is Super.

d.

Set

CollectorName

from

Step 2a

.

FortiSIEM 6.3.1 500F Collector Configuration Guide

11

Fortinet Technologies Inc.

Summary of Contents for FSM-500F

Page 1: ...500F Collector Configuration Guide FortiSIEM 6 3 1...

Page 2: ...ps support fortinet com FORTINET TRAINING CERTIFICATION PROGRAM https www fortinet com training certification NSE INSTITUTE https training fortinet com FORTIGUARD CENTER https www fortiguard com END U...

Page 3: ...FortiSIEM 14 Factory Reset 15 Step 1 Uninstall FortiSIEM application 15 Step 2 Reinstall FortiSIEM application 15 Upgrading FortiSIEM Collector 15 Appliance Re image 15 Step 1 Create Bootable Linux I...

Page 4: ...ct FSM 500F to the network by connecting an Ethernet cable to Port1 Before proceeding to the next step connecting Ethernet cable to Port1 is required for Network configuration Step 2 Power On the FSM...

Page 5: ...er diagnose hardware info Displays system hardware information like CPUs Memory and RAID information diagnose interface detail port0 Displays interface status Step 4 Configure FortiSIEM via GUI 1 Log...

Page 6: ...up 5 Select your Country and press Next 6 Select the Country and City for your timezone and press Next 7 Select 1 Collector Press Next FortiSIEM 6 3 1 500F Collector Configuration Guide 6 Fortinet Tec...

Page 7: ...IPv6 Dual Stack Choose 1 for IPv4 only choose 2 for IPv6 only or choose 3 for both IPv4 and IPv6 10 If you choose 1 IPv4 or choose 3 Both IPv4 and IPv6 and press Next then you will move to step 11 If...

Page 8: ...n step 9 then you will need to skip to step 13 If you chose 2 or 3 in step 9 then you will configure the IPv6 network by entering the following fields then press Next Option Description IPv6 Address T...

Page 9: ...n be resolved by your DNS Server entered in the previous step and responds to ping The host can either be an internal host or a public domain host like google com For migration to complete the system...

Page 10: ...llowing table Option Description r The FortiSIEM component being configured z The time zone being configured i IPv4 formatted address m Address of the subnet mask g Address of the gateway server used...

Page 11: ...nt Workers Note Rather than using IP addresses a DNS name is recommended The reasoning is should the IP addressing change it becomes a matter of updating the DNS rather than modifying the Event Worker...

Page 12: ...If a Supervisor node is only used then enter the IP of the Supervisor node Multiple IP addresses can be entered on separate lines In this case the Collectors will load balance the upload of events to...

Page 13: ...Email 5 Under Collectors click New 6 Enter the Collector Name Guaranteed EPS Start Time and End Time The last two values could be set as Unlimited Guaranteed EPS is the EPS that the Collector will al...

Page 14: ...ion created on the Super d Set CollectorName from Step 6 by command line for example phProvisionCollector add admin Admin 11 172 30 53 130 ORG1289 CO1289 A message will display after the completion Co...

Page 15: ...RAID Information is NOT applicable to FSM 500F model 4 To install FortiSIEM Collector run execute factoryreset Note This script takes 5 minutes to complete FortiSIEM Collector installation Follow the...

Page 16: ...2A for staging via USB Follow Step 2B for staging via an NFS server Step 2A USB Staging 1 Connect an 8 GB USB Drive to the system desktop or laptop 2 Open Windows Explorer right click Drive click Form...

Page 17: ...he USB drive 7 Save the options and quit set up Step 5 Re image the 500F If you followed Step 2A USB Staging continue with Step 5A here If you followed Step 2B NFS Staging follow Step 5B here Step 5A...

Page 18: ...ot disk 29 5GB sudo fdisk l Note This drive will be referred to as dev sdb in the following steps 5 Enter into root while in the terminal by using the following command sudo s 6 Mount the NFS share to...

Page 19: ...d Fortinet disclaims all warranties whether express or implied except to the extent Fortinet enters a binding written contract signed by Fortinet s General Counsel with a purchaser that expressly warr...

Reviews: