<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FortiGate logs forwarded from FortiAnalyzer not extracting timestamp in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/FortiGate-logs-forwarded-from-FortiAnalyzer-not-extracting/m-p/517332#M87545</link>
    <description>&lt;P&gt;After upgrading FortiAnalyzer (FAZ) to 6.2.3, I'm seeing Splunk timestamping issues from the FortiGate (FGT) logs it forwards to Splunk. To reiterate, FGT logs are sent to FAZ, then FAZ forwards those logs (via syslog) to Splunk. According to the FortiGate TA, this is supported, and it had worked before upgrading FAZ.&lt;/P&gt;&lt;P&gt;What I'm seeing is all logs writing to a specific timestamp (in my case, 7:00 AM). Splunk does not seem to be extracting the timestamp field correctly. The TA's settings for timestamps are pretty basic:&lt;/P&gt;&lt;P&gt;[fgt_traffic]&lt;BR /&gt;&lt;SPAN&gt;TIME_PREFIX = ^&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;Everything else is default. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;Here is a sample event, that is getting written to 7:00 AM:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;189&amp;gt;logver=506051600 timestamp=1598992014 tz="UTC-7:00" devname="&amp;lt;redacted&amp;gt;" devid="&amp;lt;redacted&amp;gt;" vd="&amp;lt;redacted&amp;gt;" date=2020-09-01 time=13:26:55 logid="0000000013" type="traffic" subtype="forward" level="notice" eventtime=1598992015 srcip=&amp;lt;redacted&amp;gt; srcport=&amp;lt;redacted&amp;gt; srcintf="&amp;lt;redacted&amp;gt;" srcintfrole="wan" dstip=&amp;lt;redacted&amp;gt; dstport=&amp;lt;redacted&amp;gt; dstintf="&amp;lt;redacted&amp;gt;" dstintfrole="lan" poluuid="&amp;lt;redacted&amp;gt;" sessionid=2089596897 proto=6 action="timeout" policyid=1 policytype="policy" service="&amp;lt;redacted&amp;gt;" dstcountry="United States" srccountry="Netherlands" trandisp="noop" duration=10 sentbyte=40 rcvdbyte=0 sentpkt=1 rcvdpkt=0 appcat="unscanned" crscore=5 craction=262144 crlevel="low"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I tried changing the TIME_PREFIX to "timestamp=" and the TIME_FORMAT to "%s". No luck. Any ideas?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 01 Sep 2020 20:36:30 GMT</pubDate>
    <dc:creator>ejwade</dc:creator>
    <dc:date>2020-09-01T20:36:30Z</dc:date>
    <item>
      <title>FortiGate logs forwarded from FortiAnalyzer not extracting timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/FortiGate-logs-forwarded-from-FortiAnalyzer-not-extracting/m-p/517332#M87545</link>
      <description>&lt;P&gt;After upgrading FortiAnalyzer (FAZ) to 6.2.3, I'm seeing Splunk timestamping issues from the FortiGate (FGT) logs it forwards to Splunk. To reiterate, FGT logs are sent to FAZ, then FAZ forwards those logs (via syslog) to Splunk. According to the FortiGate TA, this is supported, and it had worked before upgrading FAZ.&lt;/P&gt;&lt;P&gt;What I'm seeing is all logs writing to a specific timestamp (in my case, 7:00 AM). Splunk does not seem to be extracting the timestamp field correctly. The TA's settings for timestamps are pretty basic:&lt;/P&gt;&lt;P&gt;[fgt_traffic]&lt;BR /&gt;&lt;SPAN&gt;TIME_PREFIX = ^&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;Everything else is default. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;Here is a sample event, that is getting written to 7:00 AM:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;189&amp;gt;logver=506051600 timestamp=1598992014 tz="UTC-7:00" devname="&amp;lt;redacted&amp;gt;" devid="&amp;lt;redacted&amp;gt;" vd="&amp;lt;redacted&amp;gt;" date=2020-09-01 time=13:26:55 logid="0000000013" type="traffic" subtype="forward" level="notice" eventtime=1598992015 srcip=&amp;lt;redacted&amp;gt; srcport=&amp;lt;redacted&amp;gt; srcintf="&amp;lt;redacted&amp;gt;" srcintfrole="wan" dstip=&amp;lt;redacted&amp;gt; dstport=&amp;lt;redacted&amp;gt; dstintf="&amp;lt;redacted&amp;gt;" dstintfrole="lan" poluuid="&amp;lt;redacted&amp;gt;" sessionid=2089596897 proto=6 action="timeout" policyid=1 policytype="policy" service="&amp;lt;redacted&amp;gt;" dstcountry="United States" srccountry="Netherlands" trandisp="noop" duration=10 sentbyte=40 rcvdbyte=0 sentpkt=1 rcvdpkt=0 appcat="unscanned" crscore=5 craction=262144 crlevel="low"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I tried changing the TIME_PREFIX to "timestamp=" and the TIME_FORMAT to "%s". No luck. Any ideas?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2020 20:36:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/FortiGate-logs-forwarded-from-FortiAnalyzer-not-extracting/m-p/517332#M87545</guid>
      <dc:creator>ejwade</dc:creator>
      <dc:date>2020-09-01T20:36:30Z</dc:date>
    </item>
    <item>
      <title>Re: FortiGate logs forwarded from FortiAnalyzer not extracting timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/FortiGate-logs-forwarded-from-FortiAnalyzer-not-extracting/m-p/518481#M87659</link>
      <description>&lt;P&gt;I figured out a solution to this issue. I set the following in props.conf:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[fgt_log]
TIME_FORMAT = %s
TIME_PREFIX = timestamp=&lt;/LI-CODE&gt;&lt;P&gt;I had to enable/disable the log forwarding flow in FortiAnalyzer to figure out which change was the right one. I was able to determine that adding a TIME_FORMAT and TIME_PREFIX to the initial source type, "fgt_log," was the change that stuck.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2020 16:23:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/FortiGate-logs-forwarded-from-FortiAnalyzer-not-extracting/m-p/518481#M87659</guid>
      <dc:creator>ejwade</dc:creator>
      <dc:date>2020-09-08T16:23:00Z</dc:date>
    </item>
  </channel>
</rss>

