<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trouble getting data into Fortigate app in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Trouble-getting-data-into-Fortigate-app/m-p/80055#M16472</link>
    <description>&lt;P&gt;Hello Splunkers, &lt;/P&gt;

&lt;P&gt;I am facing the same issue. I have the fortinet logs indexed into the single instance of Splunk and can see the events in the search as index=fortinet_data_index, but the fortinet app is not showing the dashboard. sometime it says 'waiting for data...' and on other instance it is showing "fgt_logs" in the dashboard. &lt;/P&gt;

&lt;P&gt;I am using 'Fortinet FortiGate Add-On for Splunk' and 'Fortinet FortiGate App for Splunk' on both the machines.&lt;/P&gt;

&lt;P&gt;Please suggest me why the logs are not detected in the dashboards of fortinet app when they are visible in search with source=fortinet. &lt;/P&gt;

&lt;P&gt;any lead in this direction will be appreciable. &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Saurabh &lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Tue, 29 Sep 2020 08:09:35 GMT</pubDate>
    <dc:creator>saurabh_tek</dc:creator>
    <dc:date>2020-09-29T08:09:35Z</dc:date>
    <item>
      <title>Trouble getting data into Fortigate app</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trouble-getting-data-into-Fortigate-app/m-p/80050#M16467</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;Running Fortigate 80c with v4.0 MR3. I've downloaded and installed the fortigate splunk app but i'm having trouble getting data into it. I can see data coming into splunk from the fortigate via manager&amp;gt;Apps&amp;gt;search. I seem to have 1 source called fortigate with data labelled in this as &lt;BR /&gt;
host=machinename, sourcetype=fortigate,source=fortigate etc . This input increases so information is getting in but just doesn't seem to be indexed properly for the splunk fortigate app.&lt;/P&gt;

&lt;P&gt;The inputs.conf is as follows:&lt;/P&gt;

&lt;P&gt;[udp://514]&lt;BR /&gt;
connection_host=int ip of fortigate&lt;BR /&gt;
sourcetype=fortigate&lt;BR /&gt;
no_appending_timestamp=true&lt;/P&gt;

&lt;P&gt;I'm fairly new to splunk so i've probably got something not or misconfigured, can somebody help ?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:33:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trouble-getting-data-into-Fortigate-app/m-p/80050#M16467</guid>
      <dc:creator>rogerv</dc:creator>
      <dc:date>2020-09-28T12:33:50Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble getting data into Fortigate app</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trouble-getting-data-into-Fortigate-app/m-p/80051#M16468</link>
      <description>&lt;P&gt;Hi, do you have an example of what's not working? If you just run a search for &lt;CODE&gt;sourcetype=fortigate&lt;/CODE&gt;, what fields are displayed on the left hand side?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2012 16:24:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trouble-getting-data-into-Fortigate-app/m-p/80051#M16468</guid>
      <dc:creator>dart</dc:creator>
      <dc:date>2012-10-08T16:24:04Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble getting data into Fortigate app</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trouble-getting-data-into-Fortigate-app/m-p/80052#M16469</link>
      <description>&lt;P&gt;On the fortigate uncheck the box "Enable CSV Format"&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jan 2013 14:42:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trouble-getting-data-into-Fortigate-app/m-p/80052#M16469</guid>
      <dc:creator>wesleyveloso</dc:creator>
      <dc:date>2013-01-07T14:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble getting data into Fortigate app</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trouble-getting-data-into-Fortigate-app/m-p/80053#M16470</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;it seems, that i am having the same trouble than rogerv (by the way: is it solved? how?).&lt;/P&gt;

&lt;P&gt;logging from i.e. a fortigate 60c, v4.3, to splunk (i had to work with props.conf and transforms.conf, as there are multiple devices sending log to udp/514).&lt;/P&gt;

&lt;P&gt;"search sourcetype=fortigate*" shows events, but only sourcetype=fortigate, no sourcetypes like fortigate_traffic, or something.&lt;/P&gt;

&lt;P&gt;on the fortigates, "Enable CSV Format" is unchecked...&lt;/P&gt;

&lt;P&gt;any ideas?&lt;/P&gt;

&lt;P&gt;regards,&lt;/P&gt;

&lt;P&gt;Maik&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2013 09:25:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trouble-getting-data-into-Fortigate-app/m-p/80053#M16470</guid>
      <dc:creator>maikfischer</dc:creator>
      <dc:date>2013-08-08T09:25:34Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble getting data into Fortigate app</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trouble-getting-data-into-Fortigate-app/m-p/80054#M16471</link>
      <description>&lt;P&gt;Hi Maik, Did you solve the problem? I am suffering the same problem. help me, don't let me leave alone. Thank you in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2014 19:14:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trouble-getting-data-into-Fortigate-app/m-p/80054#M16471</guid>
      <dc:creator>hojinpk</dc:creator>
      <dc:date>2014-02-06T19:14:06Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble getting data into Fortigate app</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trouble-getting-data-into-Fortigate-app/m-p/80055#M16472</link>
      <description>&lt;P&gt;Hello Splunkers, &lt;/P&gt;

&lt;P&gt;I am facing the same issue. I have the fortinet logs indexed into the single instance of Splunk and can see the events in the search as index=fortinet_data_index, but the fortinet app is not showing the dashboard. sometime it says 'waiting for data...' and on other instance it is showing "fgt_logs" in the dashboard. &lt;/P&gt;

&lt;P&gt;I am using 'Fortinet FortiGate Add-On for Splunk' and 'Fortinet FortiGate App for Splunk' on both the machines.&lt;/P&gt;

&lt;P&gt;Please suggest me why the logs are not detected in the dashboards of fortinet app when they are visible in search with source=fortinet. &lt;/P&gt;

&lt;P&gt;any lead in this direction will be appreciable. &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Saurabh &lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:09:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trouble-getting-data-into-Fortigate-app/m-p/80055#M16472</guid>
      <dc:creator>saurabh_tek</dc:creator>
      <dc:date>2020-09-29T08:09:35Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble getting data into Fortigate app</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trouble-getting-data-into-Fortigate-app/m-p/80056#M16473</link>
      <description>&lt;P&gt;Splunkers,&lt;/P&gt;

&lt;P&gt;I faced the same issue, however managed to resolve the issue.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2017 14:22:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trouble-getting-data-into-Fortigate-app/m-p/80056#M16473</guid>
      <dc:creator>sirajnp</dc:creator>
      <dc:date>2017-03-20T14:22:29Z</dc:date>
    </item>
  </channel>
</rss>

