Hi All, I already configure ingestion log from fortigate using syslog , the log send using UDP by port 514. I also setup data inputs in splunk enterprise to recieve the data from port 514. When I perform tcp dump from splunk vm , the data successfully flowing from fortigate to splunk vm, but when I search the data from splunk web, there is no data appear. Currently I ingest the data to 1 indexer, and search the data from another search head. Please give me an advise to solve my issue. Thankyou
... View more