Hi,
When i drop traffic events on a Heavy Forwarder (fgt_traffic) my stanza don't work, its weird because in another heavy forwarder i have the same configuration and its works, mi props.conf and transforms.conf are:
props.conf
# FILTRO Eventos Fortinet Traffic
[fgt_log]
TRANSFORMS-filtro = filtrado_fortinet_traffic
transforms.conf
[filtrado_fortinet_traffic]
SOURCE_KEY = _raw
REGEX = \stype\=\"traffic\"\s
DEST_KEY = queue
FORMAT = nullQueue
best regards.
Diego.
Hi,
Affirmative I put the same files on the first Heavy forwarder. yes I restart the HF after loading the files.
I'll close this question because the fortinets managers applied a filter on his appliances, to solve the issue I applied a filter because Fortinet didn't sent the corrects log files types.
thank you again Rich.
best regards.
Hi,
Affirmative I put the same files on the first Heavy forwarder. yes I restart the HF after loading the files.
I'll close this question because the fortinets managers applied a filter on his appliances, to solve the issue I applied a filter because Fortinet didn't sent the corrects log files types.
thank you again Rich.
best regards.