<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Create Splunk Alert for fortinet VPN tunnel status in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Create-Splunk-Alert-for-fortinet-VPN-tunnel-status/m-p/512252#M17594</link>
    <description>&lt;P&gt;Hi fellow Splunkers,&lt;/P&gt;&lt;P&gt;I want to create alert with these conditions:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;alert triggered when any of the VPNs go down.&lt;/LI&gt;&lt;LI&gt;alert triggered when someone brings down the tunnel.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
    <pubDate>Tue, 04 Aug 2020 03:14:13 GMT</pubDate>
    <dc:creator>mufthmu</dc:creator>
    <dc:date>2020-08-04T03:14:13Z</dc:date>
    <item>
      <title>Create Splunk Alert for fortinet VPN tunnel status</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Create-Splunk-Alert-for-fortinet-VPN-tunnel-status/m-p/512252#M17594</link>
      <description>&lt;P&gt;Hi fellow Splunkers,&lt;/P&gt;&lt;P&gt;I want to create alert with these conditions:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;alert triggered when any of the VPNs go down.&lt;/LI&gt;&lt;LI&gt;alert triggered when someone brings down the tunnel.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 03:14:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Create-Splunk-Alert-for-fortinet-VPN-tunnel-status/m-p/512252#M17594</guid>
      <dc:creator>mufthmu</dc:creator>
      <dc:date>2020-08-04T03:14:13Z</dc:date>
    </item>
    <item>
      <title>Re: Create Splunk Alert for fortinet VPN tunnel status</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Create-Splunk-Alert-for-fortinet-VPN-tunnel-status/m-p/512366#M17599</link>
      <description>Do you have VPN and tunnel states logged in Splunk? If not, there is nothing you can do until that data is available. If you have the data, search the appropriate index(es) for events showing a down VPN or tunnel. Then save the search as an alert.&lt;BR /&gt;I'd like to be more specific, but vague questions beget vague answers.</description>
      <pubDate>Tue, 04 Aug 2020 12:51:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Create-Splunk-Alert-for-fortinet-VPN-tunnel-status/m-p/512366#M17599</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-08-04T12:51:14Z</dc:date>
    </item>
    <item>
      <title>Re: Create Splunk Alert for fortinet VPN tunnel status</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Create-Splunk-Alert-for-fortinet-VPN-tunnel-status/m-p/512401#M17600</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;yes I do, we have events coming in (assume index=fortinet).&lt;/P&gt;&lt;P&gt;However, I do not know how to write specific search query that can capture an event when the VPN is down. Also if I simply search "index = fortinet", how do you narrow the search to find events that shows a down VPN or tunnel? I could not find those events.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 15:42:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Create-Splunk-Alert-for-fortinet-VPN-tunnel-status/m-p/512401#M17600</guid>
      <dc:creator>mufthmu</dc:creator>
      <dc:date>2020-08-04T15:42:42Z</dc:date>
    </item>
    <item>
      <title>Re: Create Splunk Alert for fortinet VPN tunnel status</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Create-Splunk-Alert-for-fortinet-VPN-tunnel-status/m-p/512412#M17601</link>
      <description>&lt;P&gt;This is when it helps to understand your data.&amp;nbsp; If you're not familiar with the Fortinet logs I suggest you reach out to someone in your company who is familiar with them so he or she can tell you what to look for.&lt;/P&gt;&lt;P&gt;Some basic searches to get started include looking for the word "down"&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=fortinet "down"&lt;/LI-CODE&gt;&lt;P&gt;or the name of a VPN or tunnel&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=fortinet "&amp;lt;VPN or tunnel name&amp;gt;"&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 04 Aug 2020 16:40:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Create-Splunk-Alert-for-fortinet-VPN-tunnel-status/m-p/512412#M17601</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-08-04T16:40:04Z</dc:date>
    </item>
  </channel>
</rss>

