All Apps and Add-ons

Splunk for Fortinet FortiOS 5: How oto get the Traffic Dashboard to resolve a hostname for the destination IP address?

Monkey101
New Member

I am struggling to get the Traffic Dashboard to resolve a hostname for the destination IP address.
Is anyone able to assist with a solution for this?

0 Karma

open3s
Explorer

Hi,
We've just added a new version of the app. Please check if this solves your issues.
Thanks,
Open3S.

0 Karma

splunker12er
Motivator

No, its not solved yet

0 Karma

satishsdange
Builder

Could you please share sample logs & search, you are using.

0 Karma

splunker12er
Motivator
search source_ip="*" destination_ip="*" destination_port="*" user="*" device_name="*" application="*" sourcetype="fortios5_traffic" | fillnull device_name vdom source_interface source_ip user group destination_interface destination_ip session_type destination_port application service action policy_id bytes_sent bytes_received destination_country | stats count by device_name vdom source_interface source_ip user group destination_interface destination_ip session_type destination_port application service action policy_id bytes_sent bytes_received destination_country _time

where source_ip,destination_ip,destination_port fields are not yet extracted by the sourcetype "fortios5_traffic" ?

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...