Getting Data In

Why is Fortinet sourcetype renaming not working?

aamer86
Path Finder

Hi, 

I have clustered multi-site indexing architecture with search head cluster. 

I am getting the fortinet logs as below: 

Fortinet ==> Syslog ==> HF monitor the logs >> Indexers (index discovery)

I installed the fortinet add-on on all indexers and searchheads 
I still see logs coming under the sourcetype I defined in the inputs.conf for monitoring 

I added below a list of apps I pushed to Peers and SHs

@fortinet  @fortinet1  

Screenshot 2022-02-18 at 22.00.40.pngScreenshot 2022-02-18 at 22.01.08.png

Labels (3)
0 Karma
1 Solution

aamer86
Path Finder

Thanks @richgalloway  installing the Add-On on the HF fixed it 

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

1.  How are you trying to rename the sourcetype?

2. The TAs should be installed on the HF, too.

---
If this reply helps you, Karma would be appreciated.

aamer86
Path Finder

Thanks @richgalloway  installing the Add-On on the HF fixed it 

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...