Custom decoder and rule for Fortigate v7.x

1,850 views
Skip to first unread message

Daniel Olivares

unread,
Sep 25, 2022, 10:31:59 AM9/25/22
to Wazuh mailing list
Hello everyone, 

I would like to share a decoder and ruleset that I made for Fortigate 60E v7.X. The default decoder and rules did not work when I integrated the firewall by syslog 514.


Hopefully they can be included in the decoders and base rules.

Jose Antonio Izquierdo

unread,
Sep 25, 2022, 12:10:23 PM9/25/22
to Wazuh mailing list
Hi Daniel, Thanks for your contribution, we will analyze it and mix with the current ruleset. It may take time to be added as we are working in the new engine with new capabilities for decoder and rules. 

Thanks again. 
Best regards, 
Jose. 

Daniel Olivares

unread,
Sep 25, 2022, 2:26:29 PM9/25/22
to Jose Antonio Izquierdo, Wazuh mailing list
Thank you very much for your response and I remain attentive to any questions you have.

Cheers!


--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/831d9fe0-ce52-4c5b-90c2-528ec9e295e2n%40googlegroups.com.


--

Ada Rey

unread,
Jan 31, 2024, 3:16:04 PM1/31/24
to Wazuh | Mailing List
Did this these decoder rules ever make it into current Wazuh 4.7.1 ??? Just trying to figure out if I need to build this out more or what the status is for implementation. 

I have a 100F that I am setting up and it seems like some of the logs are coming in, but not "all". The setting it correctly set on the Fortigate for all logs. 

Thanks guys
Message has been deleted

Moshe Shvo

unread,
May 5, 2024, 2:47:58 AM5/5/24
to Wazuh | Mailing List
Hi Ada,
we are in the same situation as you - did you got answers? do you have decoder that you can share for forti 100 with fotigate v7.x machine?
thanks in advanced
Moshe

Reply all
Reply to author
Forward
0 new messages