<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SC4S TLS config for Fortigate logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/SC4S-TLS-config-for-Fortigate-logs/m-p/756599#M119997</link>
    <description>&lt;P&gt;FortiGate isn’t handled the same way as iDRAC in SC4S.&lt;/P&gt;&lt;P&gt;SC4S doesn’t have a Fortinet specific TLS listener, so swapping TCP to TLS in the env vars won’t actually do anything. Essentially, there is no SC4S_LISTEN_FORTINET_TLS_PORT, which is why your logs stopped showing up.&lt;/P&gt;&lt;P&gt;For Fortinet, you should enable TLS globally and the logs should be sent to the default TLS syslog listener, not a Fortinet-named port. The correct setup would be to enable TLS and configure a default TLS port, for example 6514 or whatever custom port you want to use. FortiGate then sends syslog over TLS to that port. Because you’re no longer using a Fortinet-specific listener, SC4S may not automatically tag the events as Fortinet based on port. The right way to handle that is to use source-based metadata overrides (by FortiGate IP or hostname) to force the correct sourcetype and index. That’s a pretty common when multiple vendors share the same TLS listener.&lt;/P&gt;&lt;P&gt;Also make sure the FortiGate side matches what SC4S is listening for. Fortinet TCP syslog often uses RFC6587 framing, and switching to TLS can change behavior depending on the options you pick. If the framing or mode doesn’t match, SC4S will accept the connection but not parse the data correctly.&lt;/P&gt;</description>
    <pubDate>Wed, 17 Dec 2025 21:50:28 GMT</pubDate>
    <dc:creator>Wander</dc:creator>
    <dc:date>2025-12-17T21:50:28Z</dc:date>
    <item>
      <title>SC4S TLS config for Fortigate logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SC4S-TLS-config-for-Fortigate-logs/m-p/756440#M119977</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;I was recieving fortigate log just fine when i was using the below config in the env file.&lt;BR /&gt;&lt;SPAN&gt;SC4S_SOURCE_TLS_ENABLE=yes&lt;/SPAN&gt;&lt;BR /&gt;SC4S_LISTEN_FORTINET_RFC6587_PORT=9XXX&lt;BR /&gt;SC4S_LISTEN_FORTINET_RFC5425_PORT=9XXX&lt;/P&gt;&lt;P&gt;After applying TLS on my other sources, for example it went from&lt;/P&gt;&lt;P&gt;SC4S_LISTEN_DELL_IDRAC_TCP_PORT=9XXX to SC4S_LISTEN_DELL_IDRAC_TLS_PORT=9XXX&lt;/P&gt;&lt;P&gt;and it worked just by replacing the protocol to TLS.&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, it's not that straight forward for the FORTINET logs.&amp;nbsp; Anyone has encountered this situation before?&lt;/P&gt;&lt;P&gt;Appreciate the help. &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Dec 2025 07:05:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SC4S-TLS-config-for-Fortigate-logs/m-p/756440#M119977</guid>
      <dc:creator>wayne333</dc:creator>
      <dc:date>2025-12-12T07:05:05Z</dc:date>
    </item>
    <item>
      <title>Re: SC4S TLS config for Fortigate logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SC4S-TLS-config-for-Fortigate-logs/m-p/756599#M119997</link>
      <description>&lt;P&gt;FortiGate isn’t handled the same way as iDRAC in SC4S.&lt;/P&gt;&lt;P&gt;SC4S doesn’t have a Fortinet specific TLS listener, so swapping TCP to TLS in the env vars won’t actually do anything. Essentially, there is no SC4S_LISTEN_FORTINET_TLS_PORT, which is why your logs stopped showing up.&lt;/P&gt;&lt;P&gt;For Fortinet, you should enable TLS globally and the logs should be sent to the default TLS syslog listener, not a Fortinet-named port. The correct setup would be to enable TLS and configure a default TLS port, for example 6514 or whatever custom port you want to use. FortiGate then sends syslog over TLS to that port. Because you’re no longer using a Fortinet-specific listener, SC4S may not automatically tag the events as Fortinet based on port. The right way to handle that is to use source-based metadata overrides (by FortiGate IP or hostname) to force the correct sourcetype and index. That’s a pretty common when multiple vendors share the same TLS listener.&lt;/P&gt;&lt;P&gt;Also make sure the FortiGate side matches what SC4S is listening for. Fortinet TCP syslog often uses RFC6587 framing, and switching to TLS can change behavior depending on the options you pick. If the framing or mode doesn’t match, SC4S will accept the connection but not parse the data correctly.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Dec 2025 21:50:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SC4S-TLS-config-for-Fortigate-logs/m-p/756599#M119997</guid>
      <dc:creator>Wander</dc:creator>
      <dc:date>2025-12-17T21:50:28Z</dc:date>
    </item>
  </channel>
</rss>

