All Apps and Add-ons

What is the difference between the Splunk for Fortinet FortiOS 5 and Splunk for Fortigate apps and how do I connect my Fortigate machine?

gerisplunk
New Member

Hello,

Can somebody please help explain the difference between the Splunk for Fortinet FortiOS 5 and Splunk for Fortigate apps?

I have a fortinet v.5.0 ...enabled log forwarding to the Splunk server. Logs are displaying in the Search & Reporting app correctly ...but how can I connect FortiOS 5 app with my fortigate? I am totally new to Splunk and maybe it's not clear what I'm searching, but is it possible to directly connect via the FortiOS 5 or Fortigate app to my the Fortigate Machine???

Thank you very much in advance

0 Karma

dfigurello
Communicator

Hi gerisplunk,

Splunk for fortinet just support fortios version 4 and this app is incompatible with fortios 5.
In "Splunk for Fortinet FortiOS 5", you have a new extractions based on the FortiOS 5 new log format.

Installation Instructions:

The Splunk for FortiOS 5 can be installed by either the Splunk app setup screen, or by manually installing and configuring the app.
Once the app is installed, you need to configure the FortiGate firewall to send the logs to Splunk (udp/513 port). Below is shown the required commands to configure the firewall to send the logs (at date, FortiOS 5 do not support syslog configuration in the Web UI):

config log syslogd setting

set status enable

set server splunk_ip

set port 513

end

I love create my own dashboards and then I create my apps, because splunk is esay. Enjoy it.

Just check this ebook:
http://www.splunk.com/goto/book

Cheers!

0 Karma

jsconner
New Member

How do I turn off logging from the fortigate if I decide to stop using splunk?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...