I using Splunk for Fortigate event log collection, and have installed the official (developed by Fortinet, Inc) Fortinet Fortigate Add-on (splunkbase app id: 2846) [link]https://splunkbase.splunk.com/app/2846/[/link] Add-on, and it shows a dashboard screen in the literature - however, I'm not able to see any pre-built dashboard in my Splunk instance.
I do have data coming in, and can search, but was hoping to leverage the prebuilt dashboard from Fortinet add-on.
Is it required I install the older "App" as well? (splunkbase app id 2800) https://splunkbase.splunk.com/app/2800/
Splunk Enterprise v7.1
Fortigate 60E, 5.4 firmware
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
Welcome to the Forums. Did you have Splunk Enterprise Security add-on installed? From my point of view, this (not free) add-on is required for the Fortinet FortiGate Add-On for Splunk. If you have Splunk without ES, you have to use Fortinet FortiGate App for Splunk https://splunkbase.splunk.com/app/2846/#/details
________________________________________________________
--- NSE 4 ---
________________________________________________________
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.