Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
FetyBas
New Contributor II

FortiSiem FSM-2000F the external collector

Good

Question, if I have a FortiSiem FSM-2000F, is the external collector necessary? Supposed mind is all in one?

If so, do I have to purchase an extra license? I have licenses for 500 devices and 5000 EPS. 

Thanks

2 Solutions
AEK

In our few deployments we only used Supervisor, but once we used a collector because we had a remote site.

Please check this page to learn more about Collector use cases.

https://docs.fortinet.com/document/fortisiem/7.1.4/fortisiem-reference-architecture-using-clickhouse...

AEK

View solution in original post

AEK
Richie_C

I am not aware of the specific integration that you mention. All of the out-of-the-box integrations can be found here:

 

FortiSIEM External Systems Configuration Guide Online | FortiSIEM 7.1.5 | Fortinet Document Library

 

You can find the requirements for each integration. 

Take a backup before making any changes

View solution in original post

6 REPLIES 6
AEK
SuperUser
SuperUser

Hi

Collector doesn't need extra license.

It is necessary to have collector, but we usually use collectors (VM or physical) when we have multiple sites, you can for example use one collector per site instead of sending logs from clients directly to central site.

AEK
AEK
FetyBas
New Contributor II

But it can be collected in the same FSM-2000F?

AEK

In our few deployments we only used Supervisor, but once we used a collector because we had a remote site.

Please check this page to learn more about Collector use cases.

https://docs.fortinet.com/document/fortisiem/7.1.4/fortisiem-reference-architecture-using-clickhouse...

AEK
AEK
Richie_C
Staff
Staff

you must have a collector if you use windows agent. Otherwise it is  optional.

 

Some reasons to use a collector might be:

 

  • If the supervisor is down, a collector can buffer events. The amount of time will vary depending of the consumed EPS.
  • A collector can help with performance. It will collect logs a performance information, zip them up and forward to the supervisor. This will leave the supervisor to do other important tasks. 
  • Data can be collected from remote locations (as already mentioned). Data is uploaded over an encrypted channel. This could be useful if you need to forward events of a unsecure network such as the internet.

I hope it helps.

Thanks

Take a backup before making any changes
FetyBas
New Contributor II

Hi
When you mention that "when you must have a collector if you use windows agent. Otherwise it is optional."
I understand that if I access it through the team's website, the collector is not necessary?
If so, you should trust him to collect on the same computer.

Reguards

Richie_C

I am not aware of the specific integration that you mention. All of the out-of-the-box integrations can be found here:

 

FortiSIEM External Systems Configuration Guide Online | FortiSIEM 7.1.5 | Fortinet Document Library

 

You can find the requirements for each integration. 

Take a backup before making any changes
Labels
Top Kudoed Authors