Getting Data In

Why is Fortinet sourcetype renaming not working?

aamer86
Path Finder

Hi, 

I have clustered multi-site indexing architecture with search head cluster. 

I am getting the fortinet logs as below: 

Fortinet ==> Syslog ==> HF monitor the logs >> Indexers (index discovery)

I installed the fortinet add-on on all indexers and searchheads 
I still see logs coming under the sourcetype I defined in the inputs.conf for monitoring 

I added below a list of apps I pushed to Peers and SHs

@fortinet  @fortinet1  

Screenshot 2022-02-18 at 22.00.40.pngScreenshot 2022-02-18 at 22.01.08.png

Labels (3)
0 Karma
1 Solution

aamer86
Path Finder

Thanks @richgalloway  installing the Add-On on the HF fixed it 

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

1.  How are you trying to rename the sourcetype?

2. The TAs should be installed on the HF, too.

---
If this reply helps you, Karma would be appreciated.

aamer86
Path Finder

Thanks @richgalloway  installing the Add-On on the HF fixed it 

Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...