All Apps and Add-ons

Fortinet FortiGate App for Splunk: When configuring Fortinet to forward data to indexers, what host will it be sending it to?

theeansible
Path Finder

I could not find this answer anywhere. I want to ask for some advice installing the Fortinet FortiGate App for Splunk.

My set-up is:
1 search head.
1 deployment-server.
1 Splunk master
2 indexers.

My question is when configuring the Fortinet to forward its data to the indexers, what host will it be sending to?
My master indexer uses indexer discovery so when i install a new forwarder, i usually just point it to the master.
Can I do the same with the Fortinet FortiGate App for Splunk?
Or would it make more sense to create a data collection node and then forward the data to the indexers?

hunters_splunk
Splunk Employee
Splunk Employee

Hi theeansible,

Indexer discovery works like this:
1. Peers report their receiving ports to master node
2. Forwarders poll master node to get the latest list of peer nodes
3. Forwarders send data to the peers in the list
4. A peer can be added or removed without affecting the forwarder configurations

Therefore, you can configure indexer discover on both the master node and forwarders, but forwarders still need to forward data to the indexers - it's just forwarders dynamically retrieve a list of indexers from the master node.
You install the Fortinet add-on on your forwarders and the add-on will automatically forward collected data to the indexers. Fortinet app must be installed on the search head because an app primarily contains search-time knowledge for dashboard reporting and visualizations.
For more information about where to install add-ons, please refer to documentation:

http://docs.splunk.com/Documentation/AddOns/released/Overview/Wheretoinstall

Hope it helps. Thanks!
Hunter

theeansible
Path Finder

Okay gotcha that makes lots of sense. I will be testing this out.
Now another question maybe you can answer.

The forwarder which will have the add-on installed will be receiving traffic via UDP. Will I have to create a new UDP data inputs on my indexers as well ?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...