<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to configure Splunk forwarder to receive FortiGate logs? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-forwarder-to-receive-FortiGate-logs/m-p/656661#M111196</link>
    <description>&lt;P&gt;I have a Splunk universal forwarder installed. The Splunk Enterprise is seeing the forwarder, now I want to send network firewall logs to host forwarder to be sent to Enterprise platform.&lt;/P&gt;</description>
    <pubDate>Tue, 05 Sep 2023 19:44:28 GMT</pubDate>
    <dc:creator>jejohnson</dc:creator>
    <dc:date>2023-09-05T19:44:28Z</dc:date>
    <item>
      <title>How to configure Splunk forwarder to receive FortiGate logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-forwarder-to-receive-FortiGate-logs/m-p/656661#M111196</link>
      <description>&lt;P&gt;I have a Splunk universal forwarder installed. The Splunk Enterprise is seeing the forwarder, now I want to send network firewall logs to host forwarder to be sent to Enterprise platform.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 19:44:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-forwarder-to-receive-FortiGate-logs/m-p/656661#M111196</guid>
      <dc:creator>jejohnson</dc:creator>
      <dc:date>2023-09-05T19:44:28Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Splunk forwarder to receive FortiGate logs.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-forwarder-to-receive-FortiGate-logs/m-p/656679#M111200</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/260283"&gt;@jejohnson&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Fortinet Fortigate sends its logs using syslog, so you have two choices:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;use a Universal Forwarder with a syslog server (betyer solution),&lt;/LI&gt;&lt;LI&gt;Use an Heavy Forwarder (doesn't need a syslog server).&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Using the first solutin you should configure a very little machine (also 2/4 CPUs and 4/8 GB RAM) with Linux and an rsyslog (or syslog-ng) server that writes the received syslogs in text files.&lt;/P&gt;&lt;P&gt;Then you can use the Universal Forwarder to read the files and send them to the Indexers.&lt;/P&gt;&lt;P&gt;In the UF, you have to install also the Fortinet Fortigate Add-On for Splunk (&lt;A href="https://splunkbase.splunk.com/app/2846" target="_blank"&gt;https://splunkbase.splunk.com/app/2846&lt;/A&gt;) to parse the logs.&lt;/P&gt;&lt;P&gt;This Add-On must also be installed on the Search Heads and eventually also on intermediate Heavy Forwarders (if present).&lt;/P&gt;&lt;P&gt;Plus:&lt;/P&gt;&lt;P&gt;This solution requires a less performant server and permits to write logs even if the Splunk UF is down.&lt;/P&gt;&lt;P&gt;Minus:&lt;/P&gt;&lt;P&gt;Requires manual configurations of the rsyslog and the UF.&lt;/P&gt;&lt;P&gt;The second solution, it's easier to configure because you can do everything bu GUI, but requires a more performant server (at least 8/12 CPUs and 8/12 GB RAM).&lt;/P&gt;&lt;P&gt;This solution is prefeable if you already have an Heavy Forwarder.&lt;/P&gt;&lt;P&gt;In the HF, you have to install also the Fortinet Fortigate Add-On for Splunk (&lt;A href="https://splunkbase.splunk.com/app/2846" target="_blank"&gt;https://splunkbase.splunk.com/app/2846&lt;/A&gt;) to parse the logs.&lt;/P&gt;&lt;P&gt;The Add-On must also be installed on the Search Heads and eventually also on intermediate Heavy Forwarders (if present).&lt;/P&gt;&lt;P&gt;Plus:&lt;/P&gt;&lt;P&gt;easier to implement.&lt;/P&gt;&lt;P&gt;Minus:&lt;/P&gt;&lt;P&gt;it requires a more performant server and doesn't ingest logs when Splunk is down.&lt;/P&gt;&lt;P&gt;In both the solutions, it's better to have two receivers and a Load Balancer to avoid a Single Point of Failure in case of maintenance or fail of the server-&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 13:47:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-forwarder-to-receive-FortiGate-logs/m-p/656679#M111200</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-09-05T13:47:42Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Splunk forwarder to receive FortiGate logs.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-forwarder-to-receive-FortiGate-logs/m-p/656681#M111201</link>
      <description>&lt;P&gt;Install the FortGate add-on (&lt;A href="https://splunkbase.splunk.com/app/2846" target="_blank"&gt;https://splunkbase.splunk.com/app/2846&lt;/A&gt;) on your UF and your Splunk indexers and search head(s).&amp;nbsp; That page will have installation instructions.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 13:54:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-forwarder-to-receive-FortiGate-logs/m-p/656681#M111201</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-09-05T13:54:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure Splunk forwarder to receive FortiGate logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-forwarder-to-receive-FortiGate-logs/m-p/684203#M114193</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I have the same scenerio in which i have architecture as follow:&lt;/P&gt;&lt;P&gt;Fortinet analyzer&amp;gt; syslog forwarder(UF installed on it)&amp;gt;Deployment server&amp;gt;search head/indexer&lt;/P&gt;&lt;P&gt;Could you confirm how we can install Fortinet add-on&amp;nbsp; on UF?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2024 03:58:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-forwarder-to-receive-FortiGate-logs/m-p/684203#M114193</guid>
      <dc:creator>Satyams14</dc:creator>
      <dc:date>2024-04-15T03:58:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure Splunk forwarder to receive FortiGate logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-forwarder-to-receive-FortiGate-logs/m-p/684208#M114194</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/266926"&gt;@Satyams14&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;it isn't a good idea adding a new question, even if on the same topic, to another question because with a new question you could have a quicker and probably better answer.&lt;/P&gt;&lt;P&gt;Anyway, as I said in the previous answer, you have to install the Fortinet Add-On on the UF/HF that you're using to receive data and on the Search Heads.&lt;/P&gt;&lt;P&gt;As I said I hint to use a rsyslog receiver that writes the logs on files that you read using the UF.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2024 06:52:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-forwarder-to-receive-FortiGate-logs/m-p/684208#M114194</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-04-15T06:52:59Z</dc:date>
    </item>
  </channel>
</rss>

