- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to map Fortiweb WAF Logs with Enterprise Security?
evinasco08
Explorer
04-14-2023
10:25 AM
Hi splunkers
Right now I'm getting data from FortiWeb Onpremise and I need to know if there are any security use cases I can apply to my Enterprise Security or which Splunk ES "Security Intelligent" and "Security Domains" dashboards I could associate this data with.
I hope to be clear with my doubt
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

woodcock
Esteemed Legend
04-14-2023
03:55 PM
This is not a Splunk question. This is a security or Fortiweb question. But in general, map the events to the "Network Traffic" datamodel and then leverage the usecases from there (think "Splunk Security Essentials").
