i have fortigate FW and i need to correlate its logs in splunk light.fortigate app/addon is not supported on splunk light. is it possible to do this without addon ? any guidance for configuration ?
The fortigate can send syslog data. So you could either have your fortigate send syslog directly to your splunk light server by setting up a network monitor input, or you could configure the fortigate to send syslog to a syslog server, and then monitor the syslog files there using the splunk forwarder.
Here's some links to get started.
https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-logging-reporting-54/logs.htm
http://docs.splunk.com/Documentation/SplunkLight/7.2.0/GettingStarted/Monitornetworkports
https://www.splunk.com/blog/2016/03/11/using-syslog-ng-with-splunk.html
http://docs.splunk.com/Documentation/SplunkLight/7.2.0/GettingStarted/GettingdataintoSplunkLightusin...