Splunk Cloud Platform

Best practice to send FortiMail Cloud logs to Splunk Cloud

ThuLe
Explorer

Hi,

We’re looking for guidance on the best way to ingest FortiMail Cloud logs into Splunk Cloud.

Our current environment includes:

  • Cloud: Splunk Cloud, Fortimail Cloud - Hosted
  • On-premise: SC4S serve, Heavy Forwarder and FortiAnalyzer on-prem

 

FortiMail Cloud is hosted by Fortinet, so we can’t just point it at our SC4S like we would for an on-prem appliance. We do have the option to send logs to our on-prem FortiAnalyzer, but we’re unsure if it’s better to:

  1. Route FortiMail Cloud logs → FortiAnalyzer on-prem → SC4S/HF → Splunk Cloud,
  2. Send FortiMail Cloud logs directly to SC4S via an external connection, or
  3. Use another recommended method (e.g., Fortinet APIs, log download scheduling, etc.)

Has anyone implemented a similar setup for FortiMail Cloud? Any best practices or pitfalls to avoid—especially regarding secure transport, parsing, and CIM compliance?

Thanks in advance!

Labels (2)
0 Karma
Get Updates on the Splunk Community!

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...