EasyManua.ls Logo

Fortinet FortiSIEM 500F User Manual

Fortinet FortiSIEM 500F
26 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
Page #1 background imageLoading...
Page #1 background image
FortiSIEM - 500F Collector Configuration Guide
Version 6.1.2
Question and Answer IconNeed help?

Do you have a question about the Fortinet FortiSIEM 500F and is the answer not in the manual?

Fortinet FortiSIEM 500F Specifications

General IconGeneral
BrandFortinet
ModelFortiSIEM 500F
CategoryData Loggers
LanguageEnglish

Summary

Appliance Setup

Fresh Installation

Describes the steps for a fresh installation of the FSM-500F appliance.

Step 1: Rack mount the FSM-500F Appliance

Instructions for physically mounting the FSM-500F appliance into a rack and connecting network cable.

Step 2: Power On the FSM-500F Appliance

Details on connecting power and turning on the FSM-500F appliance.

Step 3: Verify System Information

Steps to connect to the FSM-500F appliance and verify system information.

Step 4: Configure FortiSIEM via GUI

Guide to configuring FortiSIEM using the graphical user interface, starting with setting the timezone.

Select Region and Country for Timezone

Selecting the geographical region and country for the appliance's timezone configuration.

Select City for Timezone

Choosing the specific city within the selected country for accurate timezone settings.

Step 7: Select 1 Collector

Selecting the 'Collector' option as the target for configuration.

Step 8: Select Operation for Collector

Choosing the installation option, such as 'install_without_fips'.

Step 9: Enter Network Component Information

Inputting static IP address, Netmask, Gateway, and DNS Server details.

Configure Network Settings

Configuring the collector's network parameters: Host Name, IPv4 Address, Netmask, Gateway, FQDN, and DNS.

Step 10: Test Network Connectivity

Verifying network connectivity by pinging a host name or domain.

Step 11: Final Configuration Confirmation

Reviewing and confirming all configured parameters before finalizing the setup.

Run Configuration Command

Executing the configuration command with various parameters to set up the collector.

Step 5: Register Collectors

Instructions for registering the configured collector with the supervisor.

Enterprise Deployments: Register Collector

Steps to register a collector in an enterprise environment via the Supervisor UI.

Service Provider Deployments: Configure Event Worker

Steps for service provider deployments, configuring the Event Worker IP.

Add Organization Definition

Creating a new organization in FortiSIEM, defining administrative users and email.

Configure Collector Details for Organization

Adding collector details like name, EPS, start/end time within an organization.

Register Collectors via SSH Script

Registering the collector using a command-line script after UI configuration.

Step 6: Using FortiSIEM

Reference to the FortiSIEM User Guide for detailed usage information.

Factory Reset

Step 1: Uninstall FortiSIEM application

Procedure to uninstall the FortiSIEM application from the FSM-500F appliance.

Step 2: Reinstall FortiSIEM application

Steps to reinstall the FortiSIEM application using the 'execute factoryreset' command.

Upgrading FortiSIEM Collector

Information on upgrading the FortiSIEM Collector, referring to the Upgrade Guide.

Appliance Re-image

Prerequisites for Re-imaging

Lists hardware and software prerequisites needed for re-imaging the FortiSIEM appliance.

Step 1: Create Bootable Linux Image

Instructions to create a bootable Linux USB drive using Rufus and Ubuntu ISO.

Step 2: Copy FortiSIEM Image to USB

Steps to format and copy the FortiSIEM Collector image file onto a USB drive.

Step 3: Prepare 500F

Command to clean the FSM appliance and power it off before re-imaging.

Step 4: Configure BIOS to Boot USB

Steps to set the appliance's BIOS to boot from the USB drive.

Step 5: Re-image from USB Linux

Procedure to use Linux from USB to re-image the appliance's boot drive.

Migrating from Pre-6.1.2 FortiSIEM

Pre-Migration Checklist

Prerequisites required before performing the migration from an older FortiSIEM version.

Migrate Collector Installation

Steps for installing and configuring the bootloader and image for migration.

Download the Bootloader

Instructions to download the FortiSIEM bootloader from the support site.

Unzip Bootloader File

Unzipping the downloaded bootloader package to prepare for installation.

Prepare the Bootloader Script

Running the 'prepare_bootloader' script to install and configure the bootloader.

FortiSIEM Bootloader Shell

Interaction with the FortiSIEM bootloader shell after running the preparation script.

Load the FortiSIEM 6.1.2 Image

Steps to load the new FortiSIEM 6.1.2 image onto the appliance.

Log in to Bootloader Shell

Logging into the bootloader shell with root credentials and changing the password.

Mount and Link /opt Directory

Mounting the /opt directory and creating symbolic links for image management.

Run load_image Script

Executing the 'load_image' script to copy the new image to the target disk.

Copy Configuration Files

Copying essential configuration files to the /images directory for migration.

Migrate to FortiSIEM 6.1.2

Steps to complete the migration process to FortiSIEM version 6.1.2.

Unmount /opt Directory

Unmounting the /opt directory after completing file operations.

Run configFSM.sh for Migration

Executing configFSM.sh to start the migration configuration via GUI.

Set Timezone via GUI

Configuring the timezone using the graphical interface during migration.

Select Region and Timezone for Migration

Selecting the geographical region and specific timezone for the migration process.

Select Configuration Target

Choosing 'Collector' as the target for the migration configuration.

Select Migration Operation

Selecting the 'migrate_6_1_1' option to initiate the migration.

Test Connectivity for Migration

Testing network connectivity to a known internet site before final migration.

Run Migration Configuration Command

Executing the final command to complete the FortiSIEM migration.

Command Options for Migration

Explanation of the command-line options used for the migration process.

Restore HTTP Password File

Restoring the HTTP password file from backup after migration.

Re-Register to the Supervisor

Re-registering the collector to the supervisor using the update option.

Reboot the Appliance

Manually rebooting the appliance if it does not restart automatically after migration.