Azure / Azure/Azure-Sentinel

Support FortiAnalyzer Azure Monitor Log Ingestion API with CommonSecurityLog Mapping

Open
#14,981 0 comments 0 reactions 3 assignees Claimed by @hassanchawiche View on GitHub
Connector DCR enhancement feature request
Dominant language
Python
Stars
6.1k
Forks
3.8k
Avg merge
4d 7h
Merged PRs (30d)
125

Description

FortiAnalyzer v8+ now supports log ingestion via Azure Monitor Log ingestion API
https://docs.fortinet.com/document/fortianalyzer/8.0.0/new-features/766404/fortianalyzer-fluentd-supports-the-azure-monitor-log-ingestion-api

Describe the solution you'd like

FortiAnalyzer v8+ supports sending logs to Azure using the Azure Monitor Log Ingestion API. Please provide an official Microsoft Sentinel data connector and Data Collection Rule (DCR) configuration that maps FortiAnalyzer logs directly to the CommonSecurityLog table rather than requiring ingestion into a custom table.

This would enable customers to use existing Sentinel analytics, workbooks, hunting queries, and content without additional custom parsing or schema mapping.

Describe alternatives you've considered

Using the current Azure Monitor Log Ingestion API method with a custom table.
While functional, this requires custom tables, parsers, analytics rule modifications, and ongoing local maintenance, reducing compatibility with built-in Sentinel content.

Traditional AMA / Syslog / CEF remains an option, but API ingest is preferred as it reduces cost of deploying / maintaining additional servers if they are not needed

Additional context

FortiAnalyzer is commonly used as the central logging and forwarding platform for Fortinet environments. Direct support for CommonSecurityLog would simplify deployment, reduce operational overhead, and improve integration with Microsoft Sentinel.

Reference: https://docs.fortinet.com/document/fortianalyzer/8.0.0/new-features/766404/fortianalyzer-fluentd-supports-the-azure-monitor-log-ingestion-api

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.