I have clustered multi-site indexing architecture with search head cluster.
I am getting the fortinet logs as below:
Fortinet ==> Syslog ==> HF monitor the logs >> Indexers (index discovery)
I installed the fortinet add-on on all indexers and searchheads
I still see logs coming under the sourcetype I defined in the inputs.conf for monitoring
I added below a list of apps I pushed to Peers and SHs
1. How are you trying to rename the sourcetype?
2. The TAs should be installed on the HF, too.