<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Fortinet Fortigate App for Splunk Empty Dashboards in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortinet-Fortigate-App-for-Splunk-Empty-Dashboards/m-p/499753#M61545</link>
    <description>&lt;P&gt;So do you mean just put 'fgt_logs' in the search field? i don't see anything, either real time or all time for that &lt;/P&gt;</description>
    <pubDate>Mon, 18 May 2020 22:02:11 GMT</pubDate>
    <dc:creator>BrendanCO</dc:creator>
    <dc:date>2020-05-18T22:02:11Z</dc:date>
    <item>
      <title>Fortinet Fortigate App for Splunk Empty Dashboards</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortinet-Fortigate-App-for-Splunk-Empty-Dashboards/m-p/499745#M61537</link>
      <description>&lt;P&gt;I installed the Fortinet FortiGate App 1.5.1 for Splunk as well as the Fortinet FortiGate Add-On 1.6.2 for Splunk and configured the sourcetype in the props.conf file. &lt;/P&gt;

&lt;P&gt;After that I restarted the Splunk service. When I open the Fortinet FortiGate App and go to the Fortinet Network Security Overview I have nice dashboards with data. &lt;/P&gt;

&lt;P&gt;However the dashboards such as Traffic and VPN are all emtpy, even though when I open the according Searches and Reports I have data. Do I need to do something else to get the other dashboards working? I use Splunk 7.3.0.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2020 15:51:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortinet-Fortigate-App-for-Splunk-Empty-Dashboards/m-p/499745#M61537</guid>
      <dc:creator>spiced</dc:creator>
      <dc:date>2020-03-24T15:51:41Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinet Fortigate App for Splunk Empty Dashboards</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortinet-Fortigate-App-for-Splunk-Empty-Dashboards/m-p/499746#M61538</link>
      <description>&lt;P&gt;Did you enable data model acceleration?&lt;BR /&gt;
5. Enable Data Model Acceleration:&lt;BR /&gt;
Since version 1.5.0 of the app, data model acceleration is no longer enabled in default/datamodels.conf. User has to either enable data acceleration on Splunk GUI Settings-&amp;gt;Data Models-&amp;gt;Fortinet FoS Log.&lt;BR /&gt;
Or on Splunk search head, where the app is installed, create "local" folder under $SPLUNK_HOME/etc/apps/SplunkAppForFortinet/ and create a file in this "local" folder named datamodels.conf with the following content:&lt;/P&gt;

&lt;P&gt;[ftnt_fos]&lt;BR /&gt;
acceleration = 1&lt;BR /&gt;
acceleration.earliest_time = -1mon&lt;/P&gt;

&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/2800/#/details" target="_blank"&gt;https://splunkbase.splunk.com/app/2800/#/details&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:41:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortinet-Fortigate-App-for-Splunk-Empty-Dashboards/m-p/499746#M61538</guid>
      <dc:creator>jerryzhao</dc:creator>
      <dc:date>2020-09-30T04:41:49Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinet Fortigate App for Splunk Empty Dashboards</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortinet-Fortigate-App-for-Splunk-Empty-Dashboards/m-p/499747#M61539</link>
      <description>&lt;P&gt;Thank you @jerryzhao after I enabled the Data Model Acceleration, the dashboards contained the data.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Mar 2020 13:30:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortinet-Fortigate-App-for-Splunk-Empty-Dashboards/m-p/499747#M61539</guid>
      <dc:creator>spiced</dc:creator>
      <dc:date>2020-03-27T13:30:40Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinet Fortigate App for Splunk Empty Dashboards</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortinet-Fortigate-App-for-Splunk-Empty-Dashboards/m-p/499748#M61540</link>
      <description>&lt;P&gt;Hello all! I also am having this issue. My FoS data model is accelerated. When I go to the traffic dashboard, it's all there. When I go to the Overview dashboard, it is blank. Actually most of the fields are stuck on "waiting for data". &lt;/P&gt;

&lt;P&gt;Thoughts?&lt;/P&gt;</description>
      <pubDate>Fri, 15 May 2020 22:04:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortinet-Fortigate-App-for-Splunk-Empty-Dashboards/m-p/499748#M61540</guid>
      <dc:creator>BrendanCO</dc:creator>
      <dc:date>2020-05-15T22:04:41Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinet Fortigate App for Splunk Empty Dashboards</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortinet-Fortigate-App-for-Splunk-Empty-Dashboards/m-p/499749#M61541</link>
      <description>&lt;P&gt;overview dashboard is different from other dashboards. because overview page is for real time logs. Can you check in search&amp;amp;reporting  if the logs are coming in in real time? are all your servers' time in sync?&lt;/P&gt;</description>
      <pubDate>Fri, 15 May 2020 22:24:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortinet-Fortigate-App-for-Splunk-Empty-Dashboards/m-p/499749#M61541</guid>
      <dc:creator>jerryzhao</dc:creator>
      <dc:date>2020-05-15T22:24:49Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinet Fortigate App for Splunk Empty Dashboards</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortinet-Fortigate-App-for-Splunk-Empty-Dashboards/m-p/499750#M61542</link>
      <description>&lt;P&gt;They are indeed coming in in real time. Yes to time sync. It's weird. All of the other dashboards are working. &lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2020 20:32:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortinet-Fortigate-App-for-Splunk-Empty-Dashboards/m-p/499750#M61542</guid>
      <dc:creator>BrendanCO</dc:creator>
      <dc:date>2020-05-18T20:32:42Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinet Fortigate App for Splunk Empty Dashboards</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortinet-Fortigate-App-for-Splunk-Empty-Dashboards/m-p/499751#M61543</link>
      <description>&lt;P&gt;can you try running &lt;CODE&gt;fgt_logs&lt;/CODE&gt; query for last 10 minutes in real time streaming in search and reporting app? &lt;BR /&gt;
the overall dashboard runs the same query.&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2020 21:22:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortinet-Fortigate-App-for-Splunk-Empty-Dashboards/m-p/499751#M61543</guid>
      <dc:creator>jerryzhao</dc:creator>
      <dc:date>2020-05-18T21:22:16Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinet Fortigate App for Splunk Empty Dashboards</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortinet-Fortigate-App-for-Splunk-Empty-Dashboards/m-p/499752#M61544</link>
      <description>&lt;P&gt;fgt_logs macro needs to be put in query field: `fgt_logs`&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 05:28:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortinet-Fortigate-App-for-Splunk-Empty-Dashboards/m-p/499752#M61544</guid>
      <dc:creator>jerryzhao</dc:creator>
      <dc:date>2020-09-30T05:28:13Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinet Fortigate App for Splunk Empty Dashboards</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortinet-Fortigate-App-for-Splunk-Empty-Dashboards/m-p/499753#M61545</link>
      <description>&lt;P&gt;So do you mean just put 'fgt_logs' in the search field? i don't see anything, either real time or all time for that &lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2020 22:02:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortinet-Fortigate-App-for-Splunk-Empty-Dashboards/m-p/499753#M61545</guid>
      <dc:creator>BrendanCO</dc:creator>
      <dc:date>2020-05-18T22:02:11Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinet Fortigate App for Splunk Empty Dashboards</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortinet-Fortigate-App-for-Splunk-Empty-Dashboards/m-p/499754#M61546</link>
      <description>&lt;P&gt;please copy exact the string `fgt_logs`  and paste in search. it is not single quote.&lt;/P&gt;

&lt;P&gt;if there is still no result, can you check whether you use cutomized index name? can you check following: &lt;BR /&gt;
If a customized index is used for the input, it also needs to be added in admin user's default authorized list of indexes to search.&lt;BR /&gt;
In $SPLUNK_HOME/etc/system/local/authorize.conf&lt;/P&gt;

&lt;P&gt;[role_admin]&lt;BR /&gt;
srchIndexesDefault = fgt;main&lt;BR /&gt;
srchMaxTime = 8640000&lt;BR /&gt;
In this example, fgt is the index for my fortigate log input.&lt;/P&gt;</description>
      <pubDate>Tue, 19 May 2020 00:51:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortinet-Fortigate-App-for-Splunk-Empty-Dashboards/m-p/499754#M61546</guid>
      <dc:creator>jerryzhao</dc:creator>
      <dc:date>2020-05-19T00:51:24Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinet Fortigate App for Splunk Empty Dashboards</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortinet-Fortigate-App-for-Splunk-Empty-Dashboards/m-p/508536#M62444</link>
      <description>&lt;P&gt;Sorry for the delay in response. Was laid off for a bit. So when i put in 'fgt_logs' in the search field, I don't get anything. My index is simply called "fortigate".&amp;nbsp; I updated authorize.conf to the following:&lt;/P&gt;&lt;P&gt;[role_admin]&lt;BR /&gt;grantableRoles = admin&lt;BR /&gt;srchIndexesAllowed = *;_*;fortinet;main;paloalto;fgt&lt;BR /&gt;srchIndexesDefault = main&lt;BR /&gt;srchMaxTime = 8640000&lt;/P&gt;&lt;P&gt;Do I need to create a new index called fgt_logs?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jul 2020 19:18:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortinet-Fortigate-App-for-Splunk-Empty-Dashboards/m-p/508536#M62444</guid>
      <dc:creator>BrendanCO</dc:creator>
      <dc:date>2020-07-10T19:18:28Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinet Fortigate App for Splunk Empty Dashboards</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortinet-Fortigate-App-for-Splunk-Empty-Dashboards/m-p/538729#M64806</link>
      <description>&lt;P&gt;I installed Add-on installed FortigateAPP for splunk. Enabled data model acceleration. "Traffic dashboard" is showing results, however Overview dashboard is empty. Most of the macros searches is not returning any results. I am ingesting fortigate logs via SC4S, by default they goes to "netfw" - index, SC4S-source, fgt_traffic -sourcetype.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also added local/props.conf for Add-on :&lt;/P&gt;&lt;P&gt;[fortinet]&lt;BR /&gt;TRANSFORMS-force_sourcetype_fgt = force_sourcetype_fgt_traffic,force_sourcetype_fgt_utm,force_sourcetype_fgt_event&lt;BR /&gt;SHOULD_LINEMERGE = false&lt;/P&gt;&lt;P&gt;Any ideas why macros are failing?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 09:58:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortinet-Fortigate-App-for-Splunk-Empty-Dashboards/m-p/538729#M64806</guid>
      <dc:creator>Suirand1</dc:creator>
      <dc:date>2021-02-05T09:58:59Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinet Fortigate App for Splunk Empty Dashboards</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortinet-Fortigate-App-for-Splunk-Empty-Dashboards/m-p/553707#M65765</link>
      <description>&lt;P&gt;i faces same issue, and i just added the search of each dashboard on the app with index=xxx at the beginning of the search, then all dashboards worked fine&lt;/P&gt;</description>
      <pubDate>Mon, 31 May 2021 12:40:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Fortinet-Fortigate-App-for-Splunk-Empty-Dashboards/m-p/553707#M65765</guid>
      <dc:creator>islam</dc:creator>
      <dc:date>2021-05-31T12:40:56Z</dc:date>
    </item>
  </channel>
</rss>

