Skip to main content

Hi all, 
I’m having issues ingesting FortiNDR logs into Google SecOps using cfproduction docker forwarder here is the details:
 

Any thoughts why this happen?

 

Looks like config issue, double check the config, or post here with the config issue (remove sensitive info)  


Looks like config issue, double check the config, or post here with the config issue (remove sensitive info)  

It wasn’t a config issue, after raising a ticket to Google Support this issue have been fixed without requiring me to do any changes. Although, in “SIEM Settings > Available log types” it states that Fortinet NDR has a prebuilt parser but it doesn’t.


@Aphex2in got it, thanks for sharing, do press the support to give the RCA in this case. 


Reply