Overview
The Fortinet integration ingests logs from:
- FortiGate firewalls — traffic, UTM, event, and VPN logs
- FortiAnalyzer — centralized log repository
- FortiManager — device configuration audit events
Logs can be collected over the Fortinet REST API (recommended) or via Syslog forwarded to an Atatus log endpoint.
Prerequisites
- A FortiGate, FortiAnalyzer, or FortiManager device reachable from Atatus.
- An admin account with API access enabled.
Step 1: Create an API user on FortiGate
- Sign in to the FortiGate web UI.
- Go to System → Administrators → Create New → REST API Admin.
- Configure:
- Username:
atatus-siem - Admin profile: a read-only profile with Log & Report → Read
- PKI Group: none (use trusted hosts to scope access)
- Trusted Hosts: Atatus egress IP range
- Username:
- Click OK. The system displays the API key once — copy it immediately.
Note: For FortiAnalyzer or FortiManager, create an admin user with
rpc-permit readand use the JSON RPC endpoint/jsonrpc.
Step 2: Connect Fortinet in Atatus
- In Atatus, go to Security → Cloud SIEM → Integrations.
- Locate the Fortinet card and click Connect.
- Fill in the form:
| Field | Description | Example |
|---|---|---|
| Hostname | FortiGate / FortiAnalyzer / FortiManager management IP or FQDN. | firewall.example.com |
| API Token | API key generated in Step 1. | •••••••• |
| Device Type | fortigate, fortianalyzer, or fortimanager. |
fortigate |
| Verify TLS | Whether to validate the device certificate. | true |
| Poll Interval (minutes) | How often to fetch new events. | 5 |
| Enabled | Turn collection on. | true |
- Click Connect.
Verification
- The Fortinet card shows Configured.
- Logs appear in Security → Cloud SIEM → Audit Logs → Events with source
fortinet.
+1-415-800-4104