Skip to content
Discussion options

You must be logged in to vote

I ended up changing the mapping of the integration since the set rule in the pipeline mentioned above does not seem to be working for me

what I did:

  1. Go to Kibana -> side menu -> integrations -> search Fortinet FortiGate Firewall Logs
  2. Go to Integration policies, select your relevant integration
  3. Open up advanced options under your relevant method of sending the logs (in my case it is under the UDP section since that is how my FG is sending the logs)
  4. Mappings -> logs-fortinet_fortigate.log@package -> click on the magnifying glass
  5. Big manage button on the bottom right -> Edit
  6. Mappings ->event -> module -> edit the value from fortinet -> fortinet_fortigate
  7. scroll back up and just click Review

Replies: 2 comments 6 replies

Comment options

You must be logged in to vote
1 reply
@amorphys
Comment options

Answer selected by geistchevalier
Comment options

You must be logged in to vote
5 replies
@geistchevalier
Comment options

@ebdavison
Comment options

@geistchevalier
Comment options

@ebdavison
Comment options

@samuel809
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
4 participants