<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Fortinet -Fortigate Data not reflecting In ES Dashboard in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Fortinet-Fortigate-Data-not-reflecting-In-ES-Dashboard/m-p/503404#M46157</link>
    <description>&lt;P&gt;Can anyone help on my request.&lt;/P&gt;</description>
    <pubDate>Thu, 24 Oct 2019 08:06:42 GMT</pubDate>
    <dc:creator>anandhalagarasa</dc:creator>
    <dc:date>2019-10-24T08:06:42Z</dc:date>
    <item>
      <title>Fortinet -Fortigate Data not reflecting In ES Dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Fortinet-Fortigate-Data-not-reflecting-In-ES-Dashboard/m-p/503402#M46155</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;

&lt;P&gt;We are using Splunk Cloud in our environment. And we have a dedicated ES- Search head for Splunk Cloud as well. Currently we have installed the Fortinet Fortigate Add-on for Splunk (1.6.1) (&lt;A href="https://splunkbase.splunk.com/app/2846" target="_blank"&gt;https://splunkbase.splunk.com/app/2846&lt;/A&gt;) in our Heavy Forwarder and also in ES-Splunk Cloud Search head too. Based on the Add-On now we are getting the logs with the following sourcetypes fgt_traffic,fgt_event,fgt_utm.&lt;/P&gt;

&lt;P&gt;As mentioned in the app  when I checked in the ES-Splunk Cloud search head in Enterprise Security App I couldn’t able to find the Fortinet Fortigate data in dashboard as mentioned below.&lt;/P&gt;

&lt;P&gt;Details provided in the Add-On:&lt;/P&gt;

&lt;P&gt;"Verify the Add-on in Enterprise Security App&lt;BR /&gt;
Available dashboards in Enterprise Security App supported by Fortinet Fortigate Add-on for Splunk.&lt;/P&gt;

&lt;P&gt;Security Domain-&amp;gt;Access-&amp;gt;Access Center&lt;BR /&gt;
Security Domain-&amp;gt;Endpoint-&amp;gt;Malware Center&lt;BR /&gt;
Security Domain-&amp;gt;Network-&amp;gt;Traffic Center&lt;BR /&gt;
Security Domain-&amp;gt;Network-&amp;gt;Intrusion Center&lt;BR /&gt;
Security Domain-&amp;gt;Network-&amp;gt;Web Center&lt;BR /&gt;
Security Domain-&amp;gt;Network-&amp;gt;Network Changes&lt;BR /&gt;
Security Domain-&amp;gt;Network-&amp;gt;Port &amp;amp; Protocol Tracker&lt;BR /&gt;
Security Domain-&amp;gt;Identity-&amp;gt;Session Center"&lt;/P&gt;

&lt;P&gt;As recommended, I have disabled the Splunk Add-on for Fortinet as well but still the Fortinet Fortigate data is still not reflecting in ES Dashboards. Also I want to know how the data would in the Dashboard and how to know whether it is getting displayed in Dashboard or not as well.&lt;/P&gt;

&lt;P&gt;Kindly help on this query.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:35:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Fortinet-Fortigate-Data-not-reflecting-In-ES-Dashboard/m-p/503402#M46155</guid>
      <dc:creator>anandhalagarasa</dc:creator>
      <dc:date>2020-09-30T02:35:55Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinet -Fortigate Data not reflecting In ES Dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Fortinet-Fortigate-Data-not-reflecting-In-ES-Dashboard/m-p/503403#M46156</link>
      <description>&lt;P&gt;Kindly help on the query&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2019 14:40:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Fortinet-Fortigate-Data-not-reflecting-In-ES-Dashboard/m-p/503403#M46156</guid>
      <dc:creator>anandhalagarasa</dc:creator>
      <dc:date>2019-10-23T14:40:01Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinet -Fortigate Data not reflecting In ES Dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Fortinet-Fortigate-Data-not-reflecting-In-ES-Dashboard/m-p/503404#M46157</link>
      <description>&lt;P&gt;Can anyone help on my request.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2019 08:06:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Fortinet-Fortigate-Data-not-reflecting-In-ES-Dashboard/m-p/503404#M46157</guid>
      <dc:creator>anandhalagarasa</dc:creator>
      <dc:date>2019-10-24T08:06:42Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinet -Fortigate Data not reflecting In ES Dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Fortinet-Fortigate-Data-not-reflecting-In-ES-Dashboard/m-p/503405#M46158</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;please allow a few days for other people to answer as many of us were at Splunk's conference .conf19 the last few days. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;First of all, please try to understand how ES works before you install anything and may be wondering if something doesn't work like you expect it to be. &lt;/P&gt;

&lt;P&gt;Disabling your TA won't help as this will just disable all the knowledge objects that come with the app.&lt;/P&gt;

&lt;P&gt;Enable the app, restart the SH and look for the following:&lt;BR /&gt;
1. Is the data coming in the correct sourcetype as per the docs?&lt;BR /&gt;
2. Do most of the fields get extracted properly? &lt;BR /&gt;
3. Are tags applied? &lt;BR /&gt;
4. Is your network traffic data model (just one example) actually finding data? Use the base search provided in the data model to find matching events. Look out for indexes and sourcetypes in there.&lt;BR /&gt;
5. Is your data model accelerated? Use one of the ES provided tstats searches to see whether you can get any matching events. &lt;/P&gt;

&lt;P&gt;The Add-on does not bring any visualisations with it. No TA does. TAs help getting data ready to be used withing ES for example. If you want custom FortiNet visualisations, you need to get the &lt;A href="https://splunkbase.splunk.com/app/2800/"&gt;FortiGate App&lt;/A&gt; as well. &lt;/P&gt;

&lt;P&gt;Skalli&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2019 10:25:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Fortinet-Fortigate-Data-not-reflecting-In-ES-Dashboard/m-p/503405#M46158</guid>
      <dc:creator>skalliger</dc:creator>
      <dc:date>2019-10-28T10:25:16Z</dc:date>
    </item>
  </channel>
</rss>

