FortiSIEM Discussions
gauravpawar
New Contributor III

Can we add fortisiem agent while have splunk agent is in the system

Hi Team,

 

Could someone please guide me on can we add fortisiem agent while have splunk agent is in the system ?  do we need add exceptions ? What to look for before adding agents ? Is there any performance issue ? 

@Secusaurus @Anthony_E 

1 Solution
Secusaurus
Contributor III

Hi @gauravpawar,

 

I did not test it, but since these two are only logging agents (not EDR), I don't think that they interfere with each other.

It could have some performance impact, since every log is duplicated/sent twice then, but I don't think you'll notice that.

 

Give it a try on a server that is non-critical, test it for a week and then roll out to the other servers.

 

Best,

Christian

FCX #003451 | Fortinet Advanced Partner

View solution in original post

FCX #003451 | Fortinet Advanced Partner
1 REPLY 1
Secusaurus
Contributor III

Hi @gauravpawar,

 

I did not test it, but since these two are only logging agents (not EDR), I don't think that they interfere with each other.

It could have some performance impact, since every log is duplicated/sent twice then, but I don't think you'll notice that.

 

Give it a try on a server that is non-critical, test it for a week and then roll out to the other servers.

 

Best,

Christian

FCX #003451 | Fortinet Advanced Partner
FCX #003451 | Fortinet Advanced Partner