All Apps and Add-ons

the Fortinet Fortigate App for Splunk is not showing any data

lmjoin
Explorer

Hello,
the Fortinet Fortigate App for Splunk is not showing any data. search command sourcetype=fgt_traffic, or sourcetype=fgt_event, or sourcetype=fgt_utm also showing not data.

Here:- index=fortinet_firewall sourcetype="fortinet:firewall"

Tags (1)
0 Karma

skalliger
SplunkTrust
SplunkTrust

Hi, is your index getting events at all? Have you tried taking a look into the inputs.conf of the app to see the definitions there?

Skalli

0 Karma

lmjoin
Explorer

Hi, could you please suggest how to know
1) your index getting events at all?
2) Have you tried taking a look into the inputs.conf of the app to see --please share what to check path. I will share.

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!