Getting Data In

Fortinet filed extractions

g_paternicola
Path Finder

Hi everyone,

I'm getting probably an issue with the extraction of my Fortinet data. I have installed the following apps:

 

Fortinet FortiGate App for SplunkSplunkAppForFortinet

1.5.1

Fortinet Fortigate Add-on for SplunkSplunk_TA_fortinet_fortigate1.6.2

 

Does anyone know the different of the field action and ftnt_action? because I'm getting different results there. 

In field action do I have for example "blocked" but in ftnt_action do I have "detected" and also "dropped". This is a bit confusing while I'm trying to get only blocked attacks. 

Could someone please help me?

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...