Hi,
We’re looking for guidance on the best way to ingest FortiMail Cloud logs into Splunk Cloud.
Our current environment includes:
FortiMail Cloud is hosted by Fortinet, so we can’t just point it at our SC4S like we would for an on-prem appliance. We do have the option to send logs to our on-prem FortiAnalyzer, but we’re unsure if it’s better to:
Has anyone implemented a similar setup for FortiMail Cloud? Any best practices or pitfalls to avoid—especially regarding secure transport, parsing, and CIM compliance?
Thanks in advance!