All Apps and Add-ons

Splunk for Fortinet FortiOS 5: How oto get the Traffic Dashboard to resolve a hostname for the destination IP address?

Monkey101
New Member

I am struggling to get the Traffic Dashboard to resolve a hostname for the destination IP address.
Is anyone able to assist with a solution for this?

0 Karma

open3s
Explorer

Hi,
We've just added a new version of the app. Please check if this solves your issues.
Thanks,
Open3S.

0 Karma

splunker12er
Motivator

No, its not solved yet

0 Karma

satishsdange
Builder

Could you please share sample logs & search, you are using.

0 Karma

splunker12er
Motivator
search source_ip="*" destination_ip="*" destination_port="*" user="*" device_name="*" application="*" sourcetype="fortios5_traffic" | fillnull device_name vdom source_interface source_ip user group destination_interface destination_ip session_type destination_port application service action policy_id bytes_sent bytes_received destination_country | stats count by device_name vdom source_interface source_ip user group destination_interface destination_ip session_type destination_port application service action policy_id bytes_sent bytes_received destination_country _time

where source_ip,destination_ip,destination_port fields are not yet extracted by the sourcetype "fortios5_traffic" ?

0 Karma
Get Updates on the Splunk Community!

Fueling your curiosity with new Splunk ILT and eLearning courses

At Splunk Education, we’re driven by curiosity—both ours and yours! That’s why we’re committed to delivering ...

Splunk AI Assistant for SPL 1.1.0 | Now Personalized to Your Environment for Greater ...

Splunk AI Assistant for SPL has transformed how users interact with Splunk, making it easier than ever to ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureOn Demand Now Step boldly into the AI revolution with enhanced security ...