Getting Data In

Why is Fortinet sourcetype renaming not working?

aamer86
Path Finder

Hi, 

I have clustered multi-site indexing architecture with search head cluster. 

I am getting the fortinet logs as below: 

Fortinet ==> Syslog ==> HF monitor the logs >> Indexers (index discovery)

I installed the fortinet add-on on all indexers and searchheads 
I still see logs coming under the sourcetype I defined in the inputs.conf for monitoring 

I added below a list of apps I pushed to Peers and SHs

@fortinet  @fortinet1  

Screenshot 2022-02-18 at 22.00.40.pngScreenshot 2022-02-18 at 22.01.08.png

Labels (3)
0 Karma
1 Solution

aamer86
Path Finder

Thanks @richgalloway  installing the Add-On on the HF fixed it 

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

1.  How are you trying to rename the sourcetype?

2. The TAs should be installed on the HF, too.

---
If this reply helps you, Karma would be appreciated.

aamer86
Path Finder

Thanks @richgalloway  installing the Add-On on the HF fixed it 

Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...