enotspe / fortinet-2-elasticsearch

Fortinet products logs to Elasticsearch
Apache License 2.0
89 stars 39 forks source link

I can't discover Fortigate log #49

Closed ginobyte closed 4 months ago

ginobyte commented 1 year ago

HI, I'm newby of ELK Stack, I'm working now with FortiManager&FortiAnalyzer, and I'm courious to try FortiDragon :) , I've started with Bitnami distribution ELK stack. I've followed your guide step-by-step , I stopped and unistalled Filebeat, I' see the syslog traffic incoming from UDP port but I don't discover any data stream Fortinet Log ...Any Idea ??

Thanks for your help....if you need to see some configurations file or log I can show you..it's a Lab environnement.

enotspe commented 1 year ago

Hello,

FortiDragon uses differente indeces than Filebeat. If you have the default config of FortiDragon, then you should have a Data View named logs-fortinet.fortigate*.

enotspe commented 4 months ago

we have a new and much simpler installation procedure