Skip to content
English
  • There are no suggestions because the search field is empty.

Fortinet FortiEDR Integration

AgileBlue's SecOps platform can monitor security, system, and audit events generated by Fortinet FortiEDR, collected over syslog or via log file from your FortiEDR Central Manager.

Supported Data Streams

By forwarding syslog from your FortiEDR Central Manager, AgileBlue is able to ingest the following event types:

  • Security Events – detected threats, blocked processes, and suspicious behavior identified by your FortiEDR Collectors
  • System Events – health and operational status of FortiEDR components, including Central Manager and Collector status updates
  • Audit Trail – administrative changes, policy modifications, and console login activity

Supported Versions

The integration is tested against the following Fortinet versions:

  • Fortinet FortiEDR 5.0.0 and later

Before You Begin

Have the following in place before you start:

  • An administrator account for the FortiEDR Central Manager console, with rights to modify Export Settings and Playbook policies
  • Network connectivity from the FortiEDR Central Manager to the device running your Cerulean Agent in syslog mode
  • Firewall rules permitting syslog traffic between the Central Manager and the Cerulean Agent on the port AgileBlue provides
  • An active Playbook assigned to the devices you want monitored — security event notifications are triggered by Playbooks, not by the export destination alone

Setup Steps (Syslog Export)

  1. Follow this guide to configure a target Cerulean Agent as your Syslog Collector
    1. NOTE: If you have previously configured syslog collection on the AgileBlue platform, you can skip step No. 1 and leverage the existing syslog agent
  2. Contact AgileBlue Support to confirm the target device is enrolled in your Syslog policy; support will respond with the dedicated port number for your FortiEDR data stream
  3. Log in to your Fortinet FortiEDR Central Manager console
  4. Navigate to Administration > Export Settings, then select the Syslog tab
  5. Click the Add (+) button to create a new syslog destination and configure the following parameters:
    1. Syslog Name: A unique, recognizable name such as AgileBlue_Syslog
    2. Host: The IP address of the device running the Cerulean Agent in syslog mode, which was configured in step one
    3. Port: The port number provided by AgileBlue Support
    4. Protocol: TCP is recommended for delivery reliability; UDP is also supported
    5. Format: Select Semicolon — this is required for your events to parse correctly
  6. Click Save to finalize the destination
  7. Locate the new destination in the list and find the Notifications pane
  8. Use the toggle sliders to enable Security Events, System Events, and Audit Trail

Setup Steps (Playbook Configuration)

Defining the syslog destination is a global setting, but security event alerts are triggered by Playbooks. Repeat these steps for each Playbook assigned to your monitored devices.

  1. In the FortiEDR Central Manager, navigate to Security Settings > Playbooks
  2. Select the Playbook policy assigned to your monitored devices
  3. In the policy actions, enable the Send Syslog Notification checkbox for each trigger you want reported to AgileBlue
  4. Click Save to apply the policy changes across your environment

Validating the Integration

Generate a few events so our team can confirm your data is arriving and parsing correctly:

  1. In Administration > Export Settings, select your AgileBlue syslog destination and click Test to send a synthetic message
  2. Log out of the FortiEDR Administration Console and log back in to generate an administrative login event
  3. Briefly toggle a non-critical notification setting to generate an audit trail event
  4. If you are working in a test environment, trigger a known-safe behavioral rule to generate a security event
  5. Notify AgileBlue Support that setup is complete; our team will confirm your events are being received and parsed as expected

Common Issues

  • No events are arriving – Confirm the Send Syslog Notification checkbox is enabled within the active Playbook, not just on the export destination, and verify the Central Manager can reach the Cerulean Agent over the assigned port.
  • Events arrive but do not parse – Verify the export Format is set to Semicolon under Administration > Export Settings.
  • Firewall obstructions – Confirm intermediate and host-based firewalls allow traffic from the FortiEDR Central Manager IP to the Cerulean Agent on the assigned port.
  • Timestamps look incorrect – Verify the time zone configured on your FortiEDR Central Manager is accurate, and share that time zone with AgileBlue Support.
  • Large events appear truncated – If your destination is configured for UDP, switch it to TCP; large security events can exceed UDP message size limits.

Need Help?

AgileBlue is always here to support you and ensure you are 100% successful. If there are any issues with the setup or if you have any questions, please reach out to AgileBlue Support.

Email: support@agileblue.com

Phone: (216) 606-9400