All Apps and Add-ons

What IP do you set on the fortigate to send logs to Splunk?

lgrachek
Explorer

Hello all,
I have 3 indexers in our setup and we would like to setup Fortigate to send logs to Splunk. what is the best way to set this up? the indexers are not clustered.

0 Karma
1 Solution

adonio
Ultra Champion

hello there,
in general, you can use one of 2 ways:
1. syslog server to collect the fortinet logs and install a Forwarder to monitor the syslog directories and
2. Heavy Forwarder listening on UDP to the fortinet firewall and sending the data to indexers
in both cases, you have 1 IP that fortinet will send data to, and from that point, data will be load balanced to the 3 Indexers
there are many many articles in this portal and in community regarding considerations on both options.
use your favorite search engine, try something like: "splunk forwarder vs. syslog"

hope it helps

View solution in original post

0 Karma

adonio
Ultra Champion

hello there,
in general, you can use one of 2 ways:
1. syslog server to collect the fortinet logs and install a Forwarder to monitor the syslog directories and
2. Heavy Forwarder listening on UDP to the fortinet firewall and sending the data to indexers
in both cases, you have 1 IP that fortinet will send data to, and from that point, data will be load balanced to the 3 Indexers
there are many many articles in this portal and in community regarding considerations on both options.
use your favorite search engine, try something like: "splunk forwarder vs. syslog"

hope it helps

0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

@lgrachek - Are you using any of the Fortigate apps or add-ons on Splunkbase? If yes, which one? Just want to make sure your post is tagged appropriately for better visibility. Thanks.

0 Karma

lgrachek
Explorer

Fortinet Fortigate Add-on for Splunk version 1.4 and Fortinet FortiGate App for Splunk version 1.4 We also have FortinetAR version 1.0.0

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...