All Apps and Add-ons

What IP do you set on the fortigate to send logs to Splunk?

lgrachek
Explorer

Hello all,
I have 3 indexers in our setup and we would like to setup Fortigate to send logs to Splunk. what is the best way to set this up? the indexers are not clustered.

0 Karma
1 Solution

adonio
Ultra Champion

hello there,
in general, you can use one of 2 ways:
1. syslog server to collect the fortinet logs and install a Forwarder to monitor the syslog directories and
2. Heavy Forwarder listening on UDP to the fortinet firewall and sending the data to indexers
in both cases, you have 1 IP that fortinet will send data to, and from that point, data will be load balanced to the 3 Indexers
there are many many articles in this portal and in community regarding considerations on both options.
use your favorite search engine, try something like: "splunk forwarder vs. syslog"

hope it helps

View solution in original post

0 Karma

adonio
Ultra Champion

hello there,
in general, you can use one of 2 ways:
1. syslog server to collect the fortinet logs and install a Forwarder to monitor the syslog directories and
2. Heavy Forwarder listening on UDP to the fortinet firewall and sending the data to indexers
in both cases, you have 1 IP that fortinet will send data to, and from that point, data will be load balanced to the 3 Indexers
there are many many articles in this portal and in community regarding considerations on both options.
use your favorite search engine, try something like: "splunk forwarder vs. syslog"

hope it helps

0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

@lgrachek - Are you using any of the Fortigate apps or add-ons on Splunkbase? If yes, which one? Just want to make sure your post is tagged appropriately for better visibility. Thanks.

0 Karma

lgrachek
Explorer

Fortinet Fortigate Add-on for Splunk version 1.4 and Fortinet FortiGate App for Splunk version 1.4 We also have FortinetAR version 1.0.0

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...