- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Fortigate Netflow not dispaly all record on Qradar QFlow
Hello team,
I configured the interfaces of a fortigate to send flows to qradar, which acts as a netflow server.
i have configuring netflow with default parameter cme from documentation in rx mode on the 'output interface.
But when we run a data upload test to the 'outside, all flows are not sent to qradar.
While with other firewall vendors the flows arrive correctly.
The parameters I set are as follows:
config system netflow
set collector-ip x.y.z.w
set collector-port 2055
set source-ip 0.0.0.0
set active-flow-timeout 1800
set inactive-flow-timeout 15
set template-tx-timeout 1800
set template-tx-counter 20
set interface-select-method auto
end
any suggestions?
Thanks for the support
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Can you confirm whether have you enabled netflow on the interface level?
Kindly go through the document below:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
