Hello, this is my first experience with SplunkCloud and I would like to ask for some help.
I am trying to forward logs from fortinet to my Heavy Forwarder, I have configured UDP port 514 and sourcetype fortigate_log as per the option presented in datainputs.
After the settings and index choice, I started searching for the events but without success.
Can you help me configure so that the events appear in both Heavy Forwarder and Splunk Cloud?
NOTE: My environment has two Heavy Forwarders and no Deployment server, the communication is direct with the Splunk Cloud.
... View more