<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Where should I install Fortinet Fortigate Add-On for Splunk? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-should-I-install-Fortinet-Fortigate-Add-On-for-Splunk/m-p/706016#M12210</link>
    <description>&lt;P&gt;Hi Jerry,&lt;BR /&gt;&lt;BR /&gt;in that case where TA is installed on both Indexer and SH,&lt;BR /&gt;Where the data input and all configurations are to be configured- on SH right (for Splunk Cloud deployment)&lt;BR /&gt;below flow?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Data sources --&amp;gt; HF(Syslog server) (TA not required)--&amp;gt; Cloud indexer (with TA)--&amp;gt; Cloud SH(with TA)&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'd also suggest if you could update the add-on documentation to include clear details pls. That would help.&lt;/P&gt;&lt;P&gt;I have Splunk cloud with ITSI (not ES) and I want to test the Fortinet Add-on&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 05 Dec 2024 08:31:38 GMT</pubDate>
    <dc:creator>SanjayM</dc:creator>
    <dc:date>2024-12-05T08:31:38Z</dc:date>
    <item>
      <title>Where should I install Fortinet Fortigate Add-On for Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-should-I-install-Fortinet-Fortigate-Add-On-for-Splunk/m-p/462536#M6720</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;We are using Splunk Cloud environment with One Adhoc Search Head and one Enterprise Security Search head.&lt;/P&gt;

&lt;P&gt;We have On-prem Deployment server, one Heavy forwarder and one syslog server (also a heavy forwarder).&lt;/P&gt;

&lt;P&gt;Fortigate firewall logs are being sent from devices ---&amp;gt; syslog server (HF) ---&amp;gt;  Splunk cloud indexers&lt;/P&gt;

&lt;P&gt;Currently, I have set index=firewall and sourcetype=fgt for Fortigate firewall logs. &lt;/P&gt;

&lt;P&gt;To have the Fortigate firewall logs on Enterprise Security dashboard (For example in Intrusion Center), where the add-on should be installed and what changes to be made?&lt;/P&gt;

&lt;P&gt;Currently the add-on (1.6.0 version) is installed on ES Search Head. Should this be uninstalled from here and installed somewhere else?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2019 09:36:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-should-I-install-Fortinet-Fortigate-Add-On-for-Splunk/m-p/462536#M6720</guid>
      <dc:creator>bsuresh1</dc:creator>
      <dc:date>2019-10-17T09:36:05Z</dc:date>
    </item>
    <item>
      <title>Re: Where should I install Fortinet Fortigate Add-On for Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-should-I-install-Fortinet-Fortigate-Add-On-for-Splunk/m-p/462537#M6721</link>
      <description>&lt;P&gt;Hi @bsuresh1 &lt;/P&gt;

&lt;P&gt;As per your requirement, you have to install Add-on on the Heavy Forwarder(HF). No need to uninstall Add-on from Search Head.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2019 10:24:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-should-I-install-Fortinet-Fortigate-Add-On-for-Splunk/m-p/462537#M6721</guid>
      <dc:creator>bhavikbhalodia</dc:creator>
      <dc:date>2019-10-17T10:24:04Z</dc:date>
    </item>
    <item>
      <title>Re: Where should I install Fortinet Fortigate Add-On for Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-should-I-install-Fortinet-Fortigate-Add-On-for-Splunk/m-p/462538#M6722</link>
      <description>&lt;P&gt;As I have already placed the Fortigate AddOn on SH and u must be parsing the logs as expected.&lt;BR /&gt;
Make sure the data models , event types and tags are in place.&lt;BR /&gt;
Validate them first as ES mostly relies on them.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2019 10:26:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-should-I-install-Fortinet-Fortigate-Add-On-for-Splunk/m-p/462538#M6722</guid>
      <dc:creator>neelamsantosh</dc:creator>
      <dc:date>2019-10-17T10:26:45Z</dc:date>
    </item>
    <item>
      <title>Re: Where should I install Fortinet Fortigate Add-On for Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-should-I-install-Fortinet-Fortigate-Add-On-for-Splunk/m-p/462539#M6723</link>
      <description>&lt;P&gt;So, should I install the Add-On on Syslog server (Heavy Forwarder)? What should be the sourcetype for fortigate logs and how the props apply?&lt;/P&gt;

&lt;P&gt;I believe based on the sourcetype, the logs get pushed to ES data model&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2019 10:47:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-should-I-install-Fortinet-Fortigate-Add-On-for-Splunk/m-p/462539#M6723</guid>
      <dc:creator>bsuresh1</dc:creator>
      <dc:date>2019-10-17T10:47:14Z</dc:date>
    </item>
    <item>
      <title>Re: Where should I install Fortinet Fortigate Add-On for Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-should-I-install-Fortinet-Fortigate-Add-On-for-Splunk/m-p/462540#M6724</link>
      <description>&lt;P&gt;keep it on search head and install it on indexers as well. &lt;BR /&gt;
syslog-&amp;gt;splunk indexers(add-on)-&amp;gt;ES searchhead(add-on)&lt;BR /&gt;
when using customized index name and sourcetypes, please refer to the documentation on how to change those in configuration for  the add-on.&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/2846/#/details"&gt;https://splunkbase.splunk.com/app/2846/#/details&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2019 19:35:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-should-I-install-Fortinet-Fortigate-Add-On-for-Splunk/m-p/462540#M6724</guid>
      <dc:creator>jerryzhao</dc:creator>
      <dc:date>2019-10-17T19:35:07Z</dc:date>
    </item>
    <item>
      <title>Re: Where should I install Fortinet Fortigate Add-On for Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-should-I-install-Fortinet-Fortigate-Add-On-for-Splunk/m-p/462541#M6725</link>
      <description>&lt;P&gt;We are using Splunk Cloud. So, couldn't install on indexers. Shoudl I install it on Syslog (HF) and ES Search Head?&lt;/P&gt;</description>
      <pubDate>Fri, 18 Oct 2019 09:24:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-should-I-install-Fortinet-Fortigate-Add-On-for-Splunk/m-p/462541#M6725</guid>
      <dc:creator>bsuresh1</dc:creator>
      <dc:date>2019-10-18T09:24:50Z</dc:date>
    </item>
    <item>
      <title>Re: Where should I install Fortinet Fortigate Add-On for Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-should-I-install-Fortinet-Fortigate-Add-On-for-Splunk/m-p/462542#M6726</link>
      <description>&lt;P&gt;even on cloud, you can ask splunk support to install it for you, right? I have seen other customers use add-on on cloud as well.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Oct 2019 17:32:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-should-I-install-Fortinet-Fortigate-Add-On-for-Splunk/m-p/462542#M6726</guid>
      <dc:creator>jerryzhao</dc:creator>
      <dc:date>2019-10-18T17:32:31Z</dc:date>
    </item>
    <item>
      <title>Re: Where should I install Fortinet Fortigate Add-On for Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-should-I-install-Fortinet-Fortigate-Add-On-for-Splunk/m-p/462543#M6727</link>
      <description>&lt;P&gt;Hi All, &lt;BR /&gt;
I have installed Add-On on heavy Forwarder (syslog server), but the sourcetype transformation is not happening. All the data is coming in as fgt_log as I defined in inputs.conf.&lt;/P&gt;

&lt;P&gt;Am I missing something?&lt;/P&gt;

&lt;P&gt;Work done by me:&lt;BR /&gt;
Installed Fortigate Add-On on Heavy Forwarder&lt;BR /&gt;
Edited inputs.conf on different app (my_syslog_inputs_app): changed sourcetype from fgt to fgt_log. Decided to keep index as "firewall"&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:34:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-should-I-install-Fortinet-Fortigate-Add-On-for-Splunk/m-p/462543#M6727</guid>
      <dc:creator>bsuresh1</dc:creator>
      <dc:date>2020-09-30T02:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: Where should I install Fortinet Fortigate Add-On for Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-should-I-install-Fortinet-Fortigate-Add-On-for-Splunk/m-p/706016#M12210</link>
      <description>&lt;P&gt;Hi Jerry,&lt;BR /&gt;&lt;BR /&gt;in that case where TA is installed on both Indexer and SH,&lt;BR /&gt;Where the data input and all configurations are to be configured- on SH right (for Splunk Cloud deployment)&lt;BR /&gt;below flow?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Data sources --&amp;gt; HF(Syslog server) (TA not required)--&amp;gt; Cloud indexer (with TA)--&amp;gt; Cloud SH(with TA)&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'd also suggest if you could update the add-on documentation to include clear details pls. That would help.&lt;/P&gt;&lt;P&gt;I have Splunk cloud with ITSI (not ES) and I want to test the Fortinet Add-on&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2024 08:31:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-should-I-install-Fortinet-Fortigate-Add-On-for-Splunk/m-p/706016#M12210</guid>
      <dc:creator>SanjayM</dc:creator>
      <dc:date>2024-12-05T08:31:38Z</dc:date>
    </item>
  </channel>
</rss>

