Splunk Enterprise

is it possible to process fortigate logs without addons in splunk light ?

itsrmidb
New Member

i have fortigate FW and i need to correlate its logs in splunk light.fortigate app/addon is not supported on splunk light. is it possible to do this without addon ? any guidance for configuration ?

Tags (1)
0 Karma

Jeremiah
Motivator

The fortigate can send syslog data. So you could either have your fortigate send syslog directly to your splunk light server by setting up a network monitor input, or you could configure the fortigate to send syslog to a syslog server, and then monitor the syslog files there using the splunk forwarder.

Here's some links to get started.

https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-logging-reporting-54/logs.htm
http://docs.splunk.com/Documentation/SplunkLight/7.2.0/GettingStarted/Monitornetworkports
https://www.splunk.com/blog/2016/03/11/using-syslog-ng-with-splunk.html
http://docs.splunk.com/Documentation/SplunkLight/7.2.0/GettingStarted/GettingdataintoSplunkLightusin...

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...