Knowledge Hub · Security

Can FirstNet's managed firewall service send logs and alerts to our SIEM?

Hosted Firewall & Network Security · Answered by FirstNet Technology Services

Short answer

Yes. FirstNet can export firewall logs and alerts to your SIEM, or provide reporting dashboards instead. The integration approach, retention period and any forwarding are confirmed during solution design, because they depend on the firewall platform and service you choose.

In detail

Options by platform:

  • Sophos Firewall as a Service: all firewalls log to Sophos Central; Standard Protection keeps logs on the firewall for seven days, Xstream adds 30-day cloud retention, and logs can be forwarded via syslog to a SIEM you manage or retained in the Sophos MDR data lake
  • Fortinet: FortiAnalyzer as a Service gives Fortinet-native log analytics hosted in South Africa, and log forwarding to an existing SIEM such as Splunk or Sentinel can be scoped separately
  • Cloudflare and Netskope: logs can be forwarded into your SIEM or reviewed by FirstNet

FortiAnalyzer is not a SIEM replacement. It sits closer to your FortiGates and provides out-of-the-box compliance reports, while your SIEM correlates events across all your sources.

Raise SIEM forwarding, retention periods and custom dashboards early in discovery, because they can change the service scope and storage sizing.

Source: FirstNet Hosted Firewall & Network Security service page →

Didn’t answer your question?

Call