<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to configure fortinet fortigate add on if using syslog server UF  to get logs into indexer from fortigate analyz in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-fortinet-fortigate-add-on-if-using-syslog/m-p/684272#M114202</link>
    <description>&lt;P&gt;It appears that the Fortinet FortiWeb Add-On receives the data from a UDP data input. The instructions on the Splunkbase page describe how to set a syslog log export configuration on FortiWeb.&lt;/P&gt;&lt;P&gt;You could install this app on your indexers or a heavy forwarder to receive the logs directly from your FortiWeb device(s), but it's generally better to have a separate syslog server to collect logs rather than rely on Splunk's udp input. Your current log pipeline looks good.&lt;/P&gt;&lt;P&gt;You could then install this app on your indexer tier so that the indexers perform index-time operations on the logs after receiving them from your syslog server.&lt;/P&gt;&lt;P&gt;This app can also go on your search head to provide macros, eventtypes, and other knowledge objects used for searching.&lt;/P&gt;&lt;P&gt;Because the app does not have any input configurations, it does not make sense to install it on a universal forwarder.&lt;/P&gt;</description>
    <pubDate>Mon, 15 Apr 2024 19:12:44 GMT</pubDate>
    <dc:creator>marnall</dc:creator>
    <dc:date>2024-04-15T19:12:44Z</dc:date>
    <item>
      <title>How to configure fortinet fortigate add on if using syslog server UF  to get logs into indexer from fortigate analyzer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-fortinet-fortigate-add-on-if-using-syslog/m-p/684222#M114195</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;We have log flow from fortigate to splunk as follows:&lt;/P&gt;&lt;P&gt;Fortigate Analyzer&amp;gt; Syslog server with UF&amp;gt;Deployment server&amp;gt; SearchHead /Indexer.&lt;/P&gt;&lt;P&gt;Kindly suggest how can i get logs using fortinet add on over indexer? will i have to install fortinet add on app over syslog server UF as well? and what data source need to be selected over indexer.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2024 09:38:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-fortinet-fortigate-add-on-if-using-syslog/m-p/684222#M114195</guid>
      <dc:creator>Satyams14</dc:creator>
      <dc:date>2024-04-15T09:38:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure fortinet fortigate add on if using syslog server UF  to get logs into indexer from fortigate analyz</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-fortinet-fortigate-add-on-if-using-syslog/m-p/684272#M114202</link>
      <description>&lt;P&gt;It appears that the Fortinet FortiWeb Add-On receives the data from a UDP data input. The instructions on the Splunkbase page describe how to set a syslog log export configuration on FortiWeb.&lt;/P&gt;&lt;P&gt;You could install this app on your indexers or a heavy forwarder to receive the logs directly from your FortiWeb device(s), but it's generally better to have a separate syslog server to collect logs rather than rely on Splunk's udp input. Your current log pipeline looks good.&lt;/P&gt;&lt;P&gt;You could then install this app on your indexer tier so that the indexers perform index-time operations on the logs after receiving them from your syslog server.&lt;/P&gt;&lt;P&gt;This app can also go on your search head to provide macros, eventtypes, and other knowledge objects used for searching.&lt;/P&gt;&lt;P&gt;Because the app does not have any input configurations, it does not make sense to install it on a universal forwarder.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2024 19:12:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-fortinet-fortigate-add-on-if-using-syslog/m-p/684272#M114202</guid>
      <dc:creator>marnall</dc:creator>
      <dc:date>2024-04-15T19:12:44Z</dc:date>
    </item>
  </channel>
</rss>

