EasyManua.ls Logo

Fortinet FortiSIEM 500F - Enterprise Deployments: Register Collector; Service Provider Deployments: Configure Event Worker

Fortinet FortiSIEM 500F
26 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
Appliance Setup
1. Log in to Supervisor with Admin privileges.
2. Go to ADMIN > Setup > Collectors and add a Collector by entering:
a. Name Collector name.
b. Guaranteed EPS This is the EPS that the Collector will always be able to send. It could send more if there is
excess EPS available.
c. Start Time and End Time set to Unlimited.
3.
SSH to the Collector and run following script to register Collectors:
phProvisionCollector --add <user> <password> <Super IP or Host> <Organization>
<CollectorName>
a.
Set user and password use the admin User Name and password for the Supervisor.
b.
Set Super IP or Host as the Supervisor's IP address.
c.
Set Organization. For Enterprise deployments, the default name is Super.
d. Set CollectorName from Step 2a.
The Collector will reboot during the Registration.
4. Go to ADMIN > Health > Collector Health to see the Collector status.
Service Provider Deployments
For Service Provider deployments, follow these steps.
1. Log in to Supervisor with Admin privileges.
2. Go to ADMIN > Settings > System > Event Worker and enter the IP of the Worker node. Click OK.
FortiSIEM 6.1.2 500F Collector Configuration Guide 10
Fortinet Technologies Inc.