All Apps and Add-ons

What IP do you set on the fortigate to send logs to Splunk?

lgrachek
Explorer

Hello all,
I have 3 indexers in our setup and we would like to setup Fortigate to send logs to Splunk. what is the best way to set this up? the indexers are not clustered.

0 Karma
1 Solution

adonio
Ultra Champion

hello there,
in general, you can use one of 2 ways:
1. syslog server to collect the fortinet logs and install a Forwarder to monitor the syslog directories and
2. Heavy Forwarder listening on UDP to the fortinet firewall and sending the data to indexers
in both cases, you have 1 IP that fortinet will send data to, and from that point, data will be load balanced to the 3 Indexers
there are many many articles in this portal and in community regarding considerations on both options.
use your favorite search engine, try something like: "splunk forwarder vs. syslog"

hope it helps

View solution in original post

0 Karma

adonio
Ultra Champion

hello there,
in general, you can use one of 2 ways:
1. syslog server to collect the fortinet logs and install a Forwarder to monitor the syslog directories and
2. Heavy Forwarder listening on UDP to the fortinet firewall and sending the data to indexers
in both cases, you have 1 IP that fortinet will send data to, and from that point, data will be load balanced to the 3 Indexers
there are many many articles in this portal and in community regarding considerations on both options.
use your favorite search engine, try something like: "splunk forwarder vs. syslog"

hope it helps

0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

@lgrachek - Are you using any of the Fortigate apps or add-ons on Splunkbase? If yes, which one? Just want to make sure your post is tagged appropriately for better visibility. Thanks.

0 Karma

lgrachek
Explorer

Fortinet Fortigate Add-on for Splunk version 1.4 and Fortinet FortiGate App for Splunk version 1.4 We also have FortinetAR version 1.0.0

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...