FortiSIEM Parser
Learn how to create custom parsers to extend the integration capability of FortiSIEM to a wider range of devices and custom applications.
-
Module 1: Introduction
-
Module 2: Regular Expressions
-
Module 3: Event Format Recognizers
-
Module 4: Parsing Instructions
-
Module 5: Switch-Case Constructs
-
Module 6: Custom CMDB Event Types
-
Module 7: Choose-When Constructsc
-
Module 8: Key Value Pair Logs
-
Module 9: Value List Logs
-
Module 10: Advanced Features
About The Course
In this course, you will learn how to create custom parsers to extend the integration capability of FortiSIEM to a wider range of devices and custom applications.
You will learn how parsers recognize the type of device or application that sent the data, extract and save key information from the log, and map the device type and log information to an event type.
Course Objectives
After completing this course, you will be able to do the following:
- Examine how FortiSIEM determines which parsers to use
- Review parser terminology and steps to create a parser
- Identify different log types and structures
- Review basic and advanced regex patterns
- Use tools for regex validation and development
- Identify appropriate uses of global and local patterns
- Define local and global patterns
- Identify common string patterns in event logs
- Create event format recognizers
- Configure parsing instructions to extract and map data
- Build collectFieldsByRegex functions
- Build setEventAttribute functions
- Add comments to parser code
- Build conditional matching logic capabilities in parsers
- Parse and normalize date and time from logs
- Add, categorize, and query the CMDB for new parser events
- Create parsers for various log types
- Manipulate extracted strings from logs
- Perform calculations on variables or attributes
- Calculate event severity with Syslog priority values
- Use advanced functions to parse JSON logs
- Enable FortiSIEM support for logs in other languages
Pre-Requisites
You must have an understanding of the topics covered in the following courses, or have equivalent experience:
- NSE 4 FortiGate Security
- NSE 4 FortiGate Infrastructure
- NSE 5 FortiSIEM
It is also recommended that you have knowledge of programming languages and regular expressions.
What's included
- 24 Hours Training Course
- Certificate
- 10 Modules
- 24/7 Support