Hello Team
I have configured Fortigate sending syslog to Wazuh server. I have made these configuration. But looks no logs were sent to Wazuh server. What can I try further?
I have done these part of things.
<remote>
<connection>syslog</connection>
<port>514</port>
<protocol>udp</protocol>
<allowed-ips>LAN_IP_RANGE</allowed-ips>
<local_ip>WAZUH SERVER IP</local_ip>
</remote>
The log has below logs (/var/log/messages)
Jul 12 17:58:10 wazuh opensearch-dashboards: {"type":"response","@timestamp":"2022-07-12T09:58:10Z","tags":[],"pid":24958,"method":"get","statusCode":200,"req":{"url":"/hosts/apis","method":"get","headers":{"host":"WAZUH_IP","connecti
on":"keep-alive","sec-ch-ua":"\".Not/A)Brand\";v=\"99\", \"Google Chrome\";v=\"103\", \"Chromium\";v=\"103\"","sec-ch-ua-mobile":"?0","user-agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/1
03.0.0.0 Safari/537.36","id":"default","pattern":"wazuh-alerts-*","accept":"application/json, text/plain, */*","osd-xsrf":"kibana","sec-ch-ua-platform":"\"Windows\"","sec-fetch-site":"same-origin","sec-fetch-mode":"cors","sec-fetch-dest"
:"empty","referer":"https://WAZUH_IP/app/wazuh","accept-encoding":"gzip, deflate, br","accept-language":"en-US,en;q=0.9"},"remoteAddress":"PC_IP","userAgent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML,
like Gecko) Chrome/103.0.0.0 Safari/537.36","referer":"https://WAZUH_IP/app/wazuh"},"res":{"statusCode":200,"responseTime":67,"contentLength":9},"message":"GET /hosts/apis 200 67ms - 9.0B"}
Jul 12 17:58:10 wazuh opensearch-dashboards: {"type":"response","@timestamp":"2022-07-12T09:58:10Z","tags":[],"pid":24958,"method":"get","statusCode":200,"req":{"url":"/api/saved_objects/_find?type=index-pattern&fields=title&fields=field
s&per_page=9999","method":"get","headers":{"host":"WAZUH_IP","connection":"keep-alive","sec-ch-ua":"\".Not/A)Brand\";v=\"99\", \"Google Chrome\";v=\"103\", \"Chromium\";v=\"103\"","sec-ch-ua-mobile":"?0","user-agent":"Mozilla/5.0 (Win
dows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36","id":"default","pattern":"wazuh-alerts-*","accept":"application/json, text/plain, */*","osd-xsrf":"kibana","sec-ch-ua-platform":"\"Windows\"
","sec-fetch-site":"same-origin","sec-fetch-mode":"cors","sec-fetch-dest":"empty","referer":"https://WAZUH_IP/app/wazuh","accept-encoding":"gzip, deflate, br","accept-language":"en-US,en;q=0.9"},"remoteAddress":"PC_IP","userAge
nt":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36","referer":"https://WAZUH_IP/app/wazuh"},"res":{"statusCode":200,"responseTime":71,"contentLength":9},"message":"GET
/api/saved_objects/_find?type=index-pattern&fields=title&fields=fields&per_page=9999 200 71ms - 9.0B"}
Jul 12 18:01:02 wazuh systemd: Created slice User Slice of root.
Jul 12 18:01:02 wazuh systemd: Started Session 958 of user root.
[root@wazuh decoders]# cat fortigate_custom.xml
<decoder name="fortigate-firewall-v3">
<prematch>^date=\S+ time=\.+ devname=\S+ devid=\S+ logid=\S+ type=\S+ subtype=\S+ </prematch>
</decoder>
<decoder name="fortigate-firewall-v3-child">
<parent>fortigate-firewall-v3</parent>
<regex>^date=(\S+) time=(\.+) devname="(\S+)" devid="(\S+)" logid="(\S+)" type="(\S+)" subtype="(\S+)" </regex>
<order>date, time, devname, devid, logid, type, subtype</order>
</decoder>
<decoder name="fortigate-firewall-v3-child">
<parent>fortigate-firewall-v3</parent>
<regex offset="after_parent"> srcip=(\S+) </regex>
<order>srcip</order>
</decoder>
<decoder name="fortigate-firewall-v3-child">
<parent>fortigate-firewall-v3</parent>
<regex offset="after_parent"> proto=(\d+) </regex>
<order>protocol</order>
</decoder>
<decoder name="fortigate-firewall-v3-child">
<parent>fortigate-firewall-v3</parent>
<regex offset="after_regex"> msg="(\.+)" </regex>
<order>message</order>
</decoder>
[root@wazuh decoders]# pwd
/var/ossec/etc/decoders
Kevin Leung
IT Security Specialist
Easy Great Technology Limited