For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex Cloud Runtime

Fortinet Fortigate

Collect Fortinet Fortigate data with Cortex Cloud.

You can configure collecting Fortinet Fortigate firewall logs using a Broker VM Syslog Collector applet or content pack integration (onboarded prior to July 26, 2026):

Fortinet Fortigate vendor
Description

Syslog Collector applet overview

If you use Fortinet Fortigate firewalls, you can forward network connection logs to Cortex Cloud using the Broker VM Syslog Collector applet in a CEF format.

Link to Syslog Collector applet instructions

Links to content pack/integration details (onboarded prior to July 26, 2026)

  • The FortiManager content pack enables managing Fortinet devices through a single console central management system and provides data normalization for FortiManager event logs ingested via Syslog into Cortex XSIAM. It contains the Fortinet FortiManager Modeling Rule, the Fortinet FortiManager Parsing Rule, and the FortiManager - Install Policy Package on Device playbook. It also includes the following integration:

    • FortiManager: Use this integration to manage Fortinet devices as a single console central management system. This integration enables executing the FortiManager - Install Policy Package on Device playbook, which installs a FortiManager firewall policy package on a given device.

  • The FortiGate content pack manages FortiGate firewalls, delivering convergence and deep security visibility across diverse network environments, and facilitating data normalization for ingested event logs. It contains the Fortinet FortiGate Modeling Rule, and the FortiGate Parsing Rule. It also includes the following integration:

    • FortiGate: Use this integration to manage Fortinet FortiGate firewall devices, leveraging the Fortinet FortiOS operating system to provide deep visibility and consistent security across environments like remote offices, campuses, and data centers. It includes commands for listing, creating, updating, moving, and deleting firewall policies, addresses (IPv4 and IPv6, including multicasts), and service groups, alongside functionalities like banning and unbanning IPs.

Last updated

Was this helpful?