<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Fortigate application in Security</title>
    <link>https://community.splunk.com/t5/Security/Splunk-Fortigate-application/m-p/33606#M1117</link>
    <description>&lt;P&gt;@ Drainy In my data inputs section I am using TCP port 1514 I did that because Splunk documentation suggests using TCP for a more reliable connection. I also have source type set to manual and source type set to fortigate. Should I change back to UDP?&lt;/P&gt;

&lt;P&gt;@MHibbin will try that and report back.&lt;/P&gt;</description>
    <pubDate>Tue, 14 Aug 2012 20:59:03 GMT</pubDate>
    <dc:creator>jscott4t</dc:creator>
    <dc:date>2012-08-14T20:59:03Z</dc:date>
    <item>
      <title>Splunk Fortigate application</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Fortigate-application/m-p/33603#M1114</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I am new to Splunk and saw the Splunk for Fortigate application and wanted to use it. I have installed Splunk and have configured a TCP port connection on a specified port. The readme says to use the sourcetype of fortigate. So I have added that in the GUI under Data inputs. Is there anything else I should be doing to get this working? Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2012 21:34:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Fortigate-application/m-p/33603#M1114</guid>
      <dc:creator>jscott4t</dc:creator>
      <dc:date>2012-08-13T21:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Fortigate application</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Fortigate-application/m-p/33604#M1115</link>
      <description>&lt;P&gt;Are you not seeing the desired results then?&lt;/P&gt;

&lt;P&gt;You should check that Splunk is receiving the raw data (events), you can do this by searching for the sourcetype in the "Search" App and then using the flashtimeline/search view... then type the following in the search bar (using the word "search" a lot, haha &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;sourcetype=fortigate&lt;/P&gt;

&lt;P&gt;You should see your raw data here (assuming you set-up the sourcetype when you set-up the TCP monitor). You should then confirm the results by navigating to the fortigate App.&lt;/P&gt;

&lt;P&gt;If you are not receiving the events in Splunk, you can use some troubleshooting tools such as tcpdump on the receiveing NIC and the relevant port. It may be there is a network issue preventing the traffic flow.&lt;/P&gt;

&lt;P&gt;Hope this helps, if you need more specific help... please update your question with more detail of the issue.&lt;/P&gt;

&lt;P&gt;Regards,&lt;/P&gt;

&lt;P&gt;MHibbin&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2012 22:04:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Fortigate-application/m-p/33604#M1115</guid>
      <dc:creator>MHibbin</dc:creator>
      <dc:date>2012-08-13T22:04:07Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Fortigate application</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Fortigate-application/m-p/33605#M1116</link>
      <description>&lt;P&gt;Have you configured your fortigate appliances to forward the logs to the Splunk server? By default this is via UDP syslog on port 514.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2012 07:09:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Fortigate-application/m-p/33605#M1116</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2012-08-14T07:09:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Fortigate application</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Fortigate-application/m-p/33606#M1117</link>
      <description>&lt;P&gt;@ Drainy In my data inputs section I am using TCP port 1514 I did that because Splunk documentation suggests using TCP for a more reliable connection. I also have source type set to manual and source type set to fortigate. Should I change back to UDP?&lt;/P&gt;

&lt;P&gt;@MHibbin will try that and report back.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2012 20:59:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Fortigate-application/m-p/33606#M1117</guid>
      <dc:creator>jscott4t</dc:creator>
      <dc:date>2012-08-14T20:59:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Fortigate application</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Fortigate-application/m-p/33607#M1118</link>
      <description>&lt;P&gt;No joy yet search returned empty.&lt;/P&gt;

&lt;P&gt;I have not setup any indexing does that matter?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2012 21:02:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Fortigate-application/m-p/33607#M1118</guid>
      <dc:creator>jscott4t</dc:creator>
      <dc:date>2012-08-14T21:02:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Fortigate application</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Fortigate-application/m-p/33608#M1119</link>
      <description>&lt;P&gt;jscott4t;&lt;/P&gt;

&lt;P&gt;Here's how I got the app to work using a FortiGate 3040B:&lt;/P&gt;

&lt;P&gt;On the FG: Aim your syslogs at the Splunk indexer on a high port - I used 5012&lt;BR /&gt;
On the Indexer: Configure a UDP Data input with:&lt;BR /&gt;
     "Source name override" = fortigate&lt;BR /&gt;
     "Set sourcetype" = manual&lt;BR /&gt;
     "Source type" = fortigate&lt;/P&gt;

&lt;P&gt;I per formed a splunk stop/clean eventdata/start and started immediately seeing FG traffic and the app started to be able to see it also.  Our FG is just in a test lab so it's not too chatty, but I am at least seeing data.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Aug 2012 19:54:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Fortigate-application/m-p/33608#M1119</guid>
      <dc:creator>rbates20148</dc:creator>
      <dc:date>2012-08-29T19:54:00Z</dc:date>
    </item>
  </channel>
</rss>

