Modal title

Modal body text goes here.

Skip to main content
NSE Institute NSE Institute
  • Library
  • Schedule
  • Certifications
  • ATC
  • Network Security Academy
  • Log in
  • Training
  • Library

FortiSIEM Parser

Learn at your own pace or choose a format that suits you best.

Download Course Description
Course Description

In this two-day course, you will learn how to create custom parsers to extend FortiSIEM’s scope to as-yet unknown devices and custom applications whose log formats would not otherwise be understood by FortiSIEM.

You will learn how parsers recognize the type of device or application that sent the data, extract and save key information from the log, and map the device type and log information to an event type.

Who Should Attend

Anyone who is responsible for day-to-day management of FortiSIEM.

Agenda
  1. Introduction
  2. Regular Expressions
  3. Parser Recognizers
  4. Collect Fields by RegEx
  5. Switch Construct
  6. Adding Events to the CMDB
  7. Choose Construct
  8. Handling Key Value Pair Logs
  9. Handling Value List Logs
  10. Advanced Features
Objectives

After completing this course, you should be able to:

  • Describe the steps to create a parser
  • Create simple regular expressions
  • Use local and global patterns
  • Identify what information to extract from the log
  • Recognize different log formats
  • Extract data and map it to variables and attributes
  • Understand pattern matching
  • Understand the switch construct
  • Understand the choose construct
  • Add events to CMDB
  • Understand key value pairs
  • Work with sets of key value pairs
  • Handle value list logs
  • Understand parser order
  • Clone a system parser
  • Add different languages
System Requirements

If you take the online format of this class, you must use a computer that has the following:

  • A high-speed Internet connection
  • An up-to-date web browser
  • A PDF viewer
  • Speakers or headphones
  • One of the following:
    • HTML5 support
    • An Up-to-date Java runtime environment (JRE) with Java plugin enabled in your web browser

You should use a wired Ethernet connection, not a Wi-Fi connection. Firewalls, including Windows Firewall or FortiClient, must allow connections to the online labs.

Get Started

Take a closer look at the content

Find a Class

Browse our schedule for upcoming classes

Product Versions

FortiSIEM 5.2

Formats
  • Self-paced online
  • Instructor-led only available as private on-site class*

* Requires a quote from training@fortinet.com. Please mention FT-ONSITE SKU.

Prerequisites

A basic understanding of programming languages and regular expressions would be an asset. It is also recommended that you have an understanding of the topics covered in NSE 5 FortiSIEM, or have equivalent experience.

Certification

This course does not have a certification exam.

Library
Schedule
You are not logged in. (Log in)
  • Library
  • Schedule
  • Certifications
  • ATC
  • Network Security Academy
Data retention summary