<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Fortigate logs are not in CIM data models in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortigate-logs-are-not-in-CIM-data-models/m-p/341991#M41282</link>
    <description>&lt;P&gt;Yes, you are right! &lt;BR /&gt;
I fixed the title of the question so now people can understand what I mean, my bad english &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 02 Nov 2017 17:37:34 GMT</pubDate>
    <dc:creator>test_qweqwe</dc:creator>
    <dc:date>2017-11-02T17:37:34Z</dc:date>
    <item>
      <title>Fortigate logs are not in CIM data models</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortigate-logs-are-not-in-CIM-data-models/m-p/341989#M41280</link>
      <description>&lt;P&gt;So, logs from Fortinet successfully come to Splunk, but not to Data Model. When I checked Pivot of SIM, there are 0 events.&lt;BR /&gt;
What should I do to fix it?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2017 13:35:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortigate-logs-are-not-in-CIM-data-models/m-p/341989#M41280</guid>
      <dc:creator>test_qweqwe</dc:creator>
      <dc:date>2017-11-02T13:35:18Z</dc:date>
    </item>
    <item>
      <title>Re: Fortigate logs are not in CIM data models</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortigate-logs-are-not-in-CIM-data-models/m-p/341990#M41281</link>
      <description>&lt;P&gt;do you mean fortigate logs are not in CIM data models?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2017 17:07:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortigate-logs-are-not-in-CIM-data-models/m-p/341990#M41281</guid>
      <dc:creator>jerryzhao</dc:creator>
      <dc:date>2017-11-02T17:07:03Z</dc:date>
    </item>
    <item>
      <title>Re: Fortigate logs are not in CIM data models</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortigate-logs-are-not-in-CIM-data-models/m-p/341991#M41282</link>
      <description>&lt;P&gt;Yes, you are right! &lt;BR /&gt;
I fixed the title of the question so now people can understand what I mean, my bad english &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2017 17:37:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortigate-logs-are-not-in-CIM-data-models/m-p/341991#M41282</guid>
      <dc:creator>test_qweqwe</dc:creator>
      <dc:date>2017-11-02T17:37:34Z</dc:date>
    </item>
    <item>
      <title>Re: Fortigate logs are not in CIM data models</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortigate-logs-are-not-in-CIM-data-models/m-p/341992#M41283</link>
      <description>&lt;P&gt;what logs are fortigate reporting? any traffic logs? by the way, have you disabled the other fortigate TA that came with Enterprise Security package and then installed our add-on?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2017 17:43:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortigate-logs-are-not-in-CIM-data-models/m-p/341992#M41283</guid>
      <dc:creator>jerryzhao</dc:creator>
      <dc:date>2017-11-02T17:43:12Z</dc:date>
    </item>
    <item>
      <title>Re: Fortigate logs are not in CIM data models</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortigate-logs-are-not-in-CIM-data-models/m-p/341993#M41284</link>
      <description>&lt;P&gt;Oh, I did not know that Enterprise Security already have fortigate TA. Okay, when I will be able to turn it off on the next working day. I will report there what I will got.&lt;/P&gt;

&lt;P&gt;About logs - any traffic logs.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2017 18:06:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortigate-logs-are-not-in-CIM-data-models/m-p/341993#M41284</guid>
      <dc:creator>test_qweqwe</dc:creator>
      <dc:date>2017-11-02T18:06:28Z</dc:date>
    </item>
    <item>
      <title>Re: Fortigate logs are not in CIM data models</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortigate-logs-are-not-in-CIM-data-models/m-p/341994#M41285</link>
      <description>&lt;P&gt;Hmmm, maybe I'm blind or not understand something, but there is no default TA fortigate with EE.&lt;BR /&gt;
&lt;A href="http://prntscr.com/h5p7hu"&gt;http://prntscr.com/h5p7hu&lt;/A&gt; (screenshot)&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2017 11:56:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortigate-logs-are-not-in-CIM-data-models/m-p/341994#M41285</guid>
      <dc:creator>test_qweqwe</dc:creator>
      <dc:date>2017-11-03T11:56:46Z</dc:date>
    </item>
    <item>
      <title>Re: Fortigate logs are not in CIM data models</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortigate-logs-are-not-in-CIM-data-models/m-p/341995#M41286</link>
      <description>&lt;P&gt;that's fine. can you get anything with search sourcetype=fgt_traffic or sourcetype=fgt_event or sourcetype=fgt_utm?&lt;BR /&gt;
i noticed you installed our app as well. does the app show any data on dashboards?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:37:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortigate-logs-are-not-in-CIM-data-models/m-p/341995#M41286</guid>
      <dc:creator>jerryzhao</dc:creator>
      <dc:date>2020-09-29T16:37:43Z</dc:date>
    </item>
    <item>
      <title>Re: Fortigate logs are not in CIM data models</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortigate-logs-are-not-in-CIM-data-models/m-p/341996#M41287</link>
      <description>&lt;P&gt;Sourcetype=fgt_traffic and sourcetype=fgt_event worked in search. They even was in Data Summary in the tab "sourcetype". About sourcetype=fgt_utm: in Data Summary was not, in search not tried and right now I can't test it.&lt;BR /&gt;
About dashboards, when i tried by this list:&lt;/P&gt;

&lt;P&gt;Security Domain-&amp;gt;Access-&amp;gt;Access Center&lt;BR /&gt;
Security Domain-&amp;gt;Endpoint-&amp;gt;Malware Center&lt;BR /&gt;
Security Domain-&amp;gt;Network-&amp;gt;Traffic Center&lt;BR /&gt;
Security Domain-&amp;gt;Network-&amp;gt;Intrusion Center&lt;BR /&gt;
Security Domain-&amp;gt;Network-&amp;gt;Web Center&lt;BR /&gt;
Security Domain-&amp;gt;Network-&amp;gt;Network Changes&lt;BR /&gt;
Security Domain-&amp;gt;Network-&amp;gt;Port &amp;amp; Protocol Tracker&lt;BR /&gt;
Security Domain-&amp;gt;Identity-&amp;gt;Session Center&lt;/P&gt;

&lt;P&gt;There was data in few dashboards.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:34:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortigate-logs-are-not-in-CIM-data-models/m-p/341996#M41287</guid>
      <dc:creator>test_qweqwe</dc:creator>
      <dc:date>2020-09-29T16:34:06Z</dc:date>
    </item>
    <item>
      <title>Re: Fortigate logs are not in CIM data models</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortigate-logs-are-not-in-CIM-data-models/m-p/341997#M41288</link>
      <description>&lt;P&gt;sorry i didn't check back. you might have found a solution or given up, but fwiw, please make sure fgt_traffic, fgt_event, or fgt_utm sourcetypes are populated by the add-on as indication that the add-on is actually working. You can do that by search sourcetype= any of the 3 sourcetype listed above. And we can investigate further from there if fortigate logs is still not going into CIM model.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 21:38:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortigate-logs-are-not-in-CIM-data-models/m-p/341997#M41288</guid>
      <dc:creator>jerryzhao</dc:creator>
      <dc:date>2020-09-29T21:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: Fortigate logs are not in CIM data models</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortigate-logs-are-not-in-CIM-data-models/m-p/341998#M41289</link>
      <description>&lt;P&gt;I have a bit related problem, with CIM 4.12.0, ES 5.2.1 and Splunk 7.2.3 the signature from IPS says "unknown" instead of real signature sent by device. Signatures are however visible in Fortigate App for Splunk in the same Splunk instance. I can't seem to pinpoint where this gets broken. &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt; Any advice?&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jan 2019 14:21:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortigate-logs-are-not-in-CIM-data-models/m-p/341998#M41289</guid>
      <dc:creator>mikkorh</dc:creator>
      <dc:date>2019-01-04T14:21:52Z</dc:date>
    </item>
  </channel>
</rss>

