We do about 350-400 logs/sec but our hardware is more than capable of keeping up with the acceleration. I ended up spending a morning making my own dashboards that are loosely based on the FortiGate's dashboard and the Splunk app. Much more useful overall, so no need for the Splunk app.
... View more
I am having the same issue with version 1.3 of the app and add-on. The logs are definitely indexed properly but dashboards are several hours delayed at best. Seems to be an issue with the data model acceleration. Is there something that we should be doing to optimize the acceleration or the indexing for the FortiGate logs?
... View more