Hello,
the Fortinet Fortigate App for Splunk is not showing any data. search command sourcetype=fgt_traffic, or sourcetype=fgt_event, or sourcetype=fgt_utm also showing not data.
Here:- index=fortinet_firewall sourcetype="fortinet:firewall"
Hi, is your index getting events at all? Have you tried taking a look into the inputs.conf of the app to see the definitions there?
Skalli
Hi, could you please suggest how to know
1) your index getting events at all?
2) Have you tried taking a look into the inputs.conf of the app to see --please share what to check path. I will share.