Fortinet data not loading in kibana

Viewed 52

where is my fortinet data ??? Hello, I installed Elasticsearch and kibana and filebeat in ubuntu 22.04 VM and i installed FortiGate 7.2.0 in other VM in VMware workstation, I follow the steps to upload the Fortinet logs in elastic and kibana as the first screenshot, and the data is successfully received from the Filebeat Fortinet module but when i clic in "security App" i don't find anything

1

2

this my nano /etc/filebeat/modules.d/fortinet.yml:

-

 module: fortinet
  firewall:
    enabled: true

    # Set which input to use between tcp, udp (default) or file.
    var.input: udp

    # The interface to listen to syslog traffic. Defaults to
    # localhost. Set to 0.0.0.0 to bind to all available interfaces.
    var.syslog_host: 192.168.37.2

    # The port to listen for syslog traffic. Defaults to 9004.
    var.syslog_port: 9004

    # Set internal interfaces. used to override parsed network.direction
    # based on a tagged interface. Both internal and external interfaces must be
    # set to leverage this functionality.

and this my config log syslogd setting of fortigate : FortiGate-VM64 # config log syslogd setting

FortiGate-VM64 (setting) # show config log syslogd setting set status enable set server "192.168.37.2" set port 9004 end

FortiGate-VM64 (setting) #

0 Answers
Related