<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem dropping events from fortinet in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Problem-dropping-events-from-fortinet/m-p/535558#M4677</link>
    <description>Did you install the props.conf and transforms.conf files on the FIRST HF that sees the data? Did you restart the HF after loading the files?</description>
    <pubDate>Tue, 12 Jan 2021 20:48:07 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-01-12T20:48:07Z</dc:date>
    <item>
      <title>Problem dropping events from fortinet</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Problem-dropping-events-from-fortinet/m-p/535537#M4675</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;When i drop traffic events on a Heavy Forwarder (fgt_traffic) my stanza don't work, its weird because in another heavy forwarder i have the same configuration and its works, mi props.conf and transforms.conf are:&lt;/P&gt;&lt;P&gt;props.conf&lt;/P&gt;&lt;P&gt;# FILTRO Eventos Fortinet Traffic&lt;BR /&gt;[fgt_log]&lt;BR /&gt;TRANSFORMS-filtro = filtrado_fortinet_traffic&lt;/P&gt;&lt;P&gt;transforms.conf&lt;/P&gt;&lt;P&gt;[filtrado_fortinet_traffic]&lt;BR /&gt;SOURCE_KEY = _raw&lt;BR /&gt;REGEX = \stype\=\"traffic\"\s&lt;BR /&gt;DEST_KEY = queue&lt;BR /&gt;FORMAT = nullQueue&lt;/P&gt;&lt;P&gt;best regards.&lt;/P&gt;&lt;P&gt;Diego.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jan 2021 18:22:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Problem-dropping-events-from-fortinet/m-p/535537#M4675</guid>
      <dc:creator>tdepablo88</dc:creator>
      <dc:date>2021-01-12T18:22:27Z</dc:date>
    </item>
    <item>
      <title>Re: Problem dropping events from fortinet</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Problem-dropping-events-from-fortinet/m-p/535558#M4677</link>
      <description>Did you install the props.conf and transforms.conf files on the FIRST HF that sees the data? Did you restart the HF after loading the files?</description>
      <pubDate>Tue, 12 Jan 2021 20:48:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Problem-dropping-events-from-fortinet/m-p/535558#M4677</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-01-12T20:48:07Z</dc:date>
    </item>
    <item>
      <title>Re: Problem dropping events from fortinet</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Problem-dropping-events-from-fortinet/m-p/535673#M4690</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Affirmative I put the same files on the first Heavy forwarder. yes I restart the HF after loading the files.&lt;/P&gt;&lt;P&gt;I'll close this question because the fortinets managers applied a filter on his appliances, to solve the issue I applied a filter because Fortinet didn't sent the corrects log files types.&lt;/P&gt;&lt;P&gt;thank you again Rich.&lt;/P&gt;&lt;P&gt;best regards.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 15:08:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Problem-dropping-events-from-fortinet/m-p/535673#M4690</guid>
      <dc:creator>tdepablo88</dc:creator>
      <dc:date>2021-01-13T15:08:56Z</dc:date>
    </item>
  </channel>
</rss>

