Security

Filtering Fortinet logs in splunk

islam
Explorer

Hi,

how can we filter fortinet logs from splunk like informational data type, also can i filter fori logs comming from specific ip like x.x.x.x

Labels (1)
Tags (1)
0 Karma

venkatasri
SplunkTrust
SplunkTrust

@islam do you have sample event where to find informational data type inside _raw and where ip address that you want to filter appear as host field/ in _raw event. you can send them nullQueue by using rex pattern.

0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @islam 

What exactly mean by filter, filter them at search time or while ingesting?

 

0 Karma

islam
Explorer

@venkatasri 

i need to filter them while ingesting, i don't need to index specific data types like informational or data from specific IP

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...