I am using the Fortinet Fortigate App for Splunk and I am unable to see any data in Fortigate dashboards.
When I perform a search in the app, I can see the events.
What do I have to check in order to see data in dashboards?
Tnx in advance
We have this problem too, the Fortinet App shows no data being populating. Is there a fix for this?
Here is the beginning of my props.conf file in 'C:\Program Files\Splunk\etc\apps\SplunkTAfortinet_fortigate\default'
TRANSFORMS-force_sourcetype_fgt = force_sourcetype_fgt_traffic,force_sourcetype_fgt_utm,force_sourcetype_fgt_event
SHOULD_LINEMERGE = false
I have one data input on port 1514/UDP and the sourcetype name is 'Fortinet'. Our regular search/reporting is working fine witn the incoming syslog.
I installed the 'Fortinet FortiGate App for Splunk' ver. 1.4 and 'Fortinet Fortigate Add-on for Splunk' ver. 1.4. The only other change I made was to the first section this file: 'C:\Program Files\Splunk\etc\apps\SplunkTAfortinet_fortigate\default\props.conf'
[Fortinet] TRANSFORMS-force_sourcetype_fgt = force_sourcetype_fgt_traffic,force_sourcetype_fgt_utm,force_sourcetype_fgt_event SHOULD_LINEMERGE = false
Currently I see no data in the Fortigate app, it shows 0 for device|virtual domain|session.
If I click on search within the device block, it brings me to a search with no results using string:
fgt_logs | stats dc(devid)
Can someone help us get this working?
Thank you in advance,
did you install the add-on?
could you show me what your input config looks like? a screenshot of the logs you are seeing in search?
what fortigate app and add-on version are you using?
Hey Vadim - 'Splunk for Fortigate' app is very old and was made for Splunk 5.0. If you are using latest version of Splunk, you better use 'Fortinet FortiGate App for Splunk'. Configure it on port 514 for syslogs and it will start collecting the data and reflect on the dashboards.
Hope this will help. Thanks
OK Vadim. As you mentioned that data is coming and can be fetched under searches, so dashboard should ideally populate the information. If this is not happening then probable cause is something which is causing the searching slow. Have a look on
(a) how many searches are running concurrently in the background,
(b) bottleneck - If the CPU or any other system resource is too busy/spiking e.g. are you using a VM for search head.
I am using regular workstation with Splunk on it..
I got this error in Messages section :The maximum number of real-time concurrent system-wide searches has been reached. current=8 maximum=8
okay. So regarding this error message the splunk search limit has reached thats why its giving that error.
Try stoping some less important 'running' searches from Job activity tracker on splunk and then see.
When i tried the same thing, last month in direct prod.env then dashboards got populated but now i am using some historic data (not the stream) on another env. and i am facing the same issue.
Let me know if you got some solution of this or not ? If yes, whats is that.