FortiAnalyzer v8+ now supports log ingestion via Azure Monitor Log ingestion API
https://docs.fortinet.com/document/fortianalyzer/8.0.0/new-features/766404/fortianalyzer-fluentd-supports-the-azure-monitor-log-ingestion-api
Describe the solution you'd like
FortiAnalyzer v8+ supports sending logs to Azure using the Azure Monitor Log Ingestion API. Please provide an official Microsoft Sentinel data connector and Data Collection Rule (DCR) configuration that maps FortiAnalyzer logs directly to the CommonSecurityLog table rather than requiring ingestion into a custom table.
This would enable customers to use existing Sentinel analytics, workbooks, hunting queries, and content without additional custom parsing or schema mapping.
Describe alternatives you've considered
Using the current Azure Monitor Log Ingestion API method with a custom table.
While functional, this requires custom tables, parsers, analytics rule modifications, and ongoing local maintenance, reducing compatibility with built-in Sentinel content.
Traditional AMA / Syslog / CEF remains an option, but API ingest is preferred as it reduces cost of deploying / maintaining additional servers if they are not needed
Additional context
FortiAnalyzer is commonly used as the central logging and forwarding platform for Fortinet environments. Direct support for CommonSecurityLog would simplify deployment, reduce operational overhead, and improve integration with Microsoft Sentinel.
Reference: https://docs.fortinet.com/document/fortianalyzer/8.0.0/new-features/766404/fortianalyzer-fluentd-supports-the-azure-monitor-log-ingestion-api
FortiAnalyzer v8+ now supports log ingestion via Azure Monitor Log ingestion API
https://docs.fortinet.com/document/fortianalyzer/8.0.0/new-features/766404/fortianalyzer-fluentd-supports-the-azure-monitor-log-ingestion-api
Describe the solution you'd like
FortiAnalyzer v8+ supports sending logs to Azure using the Azure Monitor Log Ingestion API. Please provide an official Microsoft Sentinel data connector and Data Collection Rule (DCR) configuration that maps FortiAnalyzer logs directly to the CommonSecurityLog table rather than requiring ingestion into a custom table.
This would enable customers to use existing Sentinel analytics, workbooks, hunting queries, and content without additional custom parsing or schema mapping.
Describe alternatives you've considered
Using the current Azure Monitor Log Ingestion API method with a custom table.
While functional, this requires custom tables, parsers, analytics rule modifications, and ongoing local maintenance, reducing compatibility with built-in Sentinel content.
Traditional AMA / Syslog / CEF remains an option, but API ingest is preferred as it reduces cost of deploying / maintaining additional servers if they are not needed
Additional context
FortiAnalyzer is commonly used as the central logging and forwarding platform for Fortinet environments. Direct support for CommonSecurityLog would simplify deployment, reduce operational overhead, and improve integration with Microsoft Sentinel.
Reference: https://docs.fortinet.com/document/fortianalyzer/8.0.0/new-features/766404/fortianalyzer-fluentd-supports-the-azure-monitor-log-ingestion-api