Skip to content
Discussion options

You must be logged in to vote

Hi. I was offline somedays. I finally achieved logs ingest. I did exactly what you said above and observed that logs were arriving to the port 9004. So then I inspected firewall config and released that I only allowed my FortiGate IP and port in the DOCKER-USER and didn't allowe it in the INPUT field. After allowing both options the logs have started to appear.

P.S. If someone has the same problem be careful with the FortiGate's IP that you allow in SO firewall because if you use Virtual Domains in FortiGate you have to consider internal routing so the IP that send logs can be different to expected.

@dougburks Thank you!!!

Replies: 1 comment 3 replies

Comment options

You must be logged in to vote
3 replies
@bdavedu
Comment options

@dougburks
Comment options

@bdavedu
Comment options

Answer selected by dougburks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants