Overview

The Fortinet integration ingests logs from:

  • FortiGate firewalls — traffic, UTM, event, and VPN logs
  • FortiAnalyzer — centralized log repository
  • FortiManager — device configuration audit events

Logs can be collected over the Fortinet REST API (recommended) or via Syslog forwarded to an Atatus log endpoint.


Prerequisites

  • A FortiGate, FortiAnalyzer, or FortiManager device reachable from Atatus.
  • An admin account with API access enabled.

Step 1: Create an API user on FortiGate

  1. Sign in to the FortiGate web UI.
  2. Go to System → Administrators → Create New → REST API Admin.
  3. Configure:
    • Username: atatus-siem
    • Admin profile: a read-only profile with Log & Report → Read
    • PKI Group: none (use trusted hosts to scope access)
    • Trusted Hosts: Atatus egress IP range
  4. Click OK. The system displays the API key once — copy it immediately.

Note: For FortiAnalyzer or FortiManager, create an admin user with rpc-permit read and use the JSON RPC endpoint /jsonrpc.


Step 2: Connect Fortinet in Atatus

  1. In Atatus, go to Security → Cloud SIEM → Integrations.
  2. Locate the Fortinet card and click Connect.
  3. Fill in the form:
Field Description Example
Hostname FortiGate / FortiAnalyzer / FortiManager management IP or FQDN. firewall.example.com
API Token API key generated in Step 1. ••••••••
Device Type fortigate, fortianalyzer, or fortimanager. fortigate
Verify TLS Whether to validate the device certificate. true
Poll Interval (minutes) How often to fetch new events. 5
Enabled Turn collection on. true
  1. Click Connect.

Verification

  • The Fortinet card shows Configured.
  • Logs appear in Security → Cloud SIEM → Audit Logs → Events with source fortinet.