We have 5 Fortigate firewalls and one FortiAnalyzer, currently the firewalls send their logs into the FortiAnalyzer.
No we want to integrate the five firewalls into our RSA SIEM, question is:
Is it recommended that we integrate the five firewalls into our SIEM or integrate only the FortiAnalyzer (which receives the logs from the five firewalls) into our SIEM is better? Please confirm and if there is a document for confirming it will be great.
Looking forward to hearing from you