-
Version2.4.40 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeStandalone Locationother (please provide detail below) Hardware SpecsExceeds minimum requirements CPU6 RAM16GB Storage for /588G Storage for /nsm588G ( part of / ) Network Traffic Collectionother (please provide detail below) Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsYes, there are additional clues in /opt/so/log/ (please provide detail below) DetailI have a fortigate running 7.x and am sending logs to my SO instance. I am receiving logs as verified with tcpdump but they do not show in ES/Kibana. I have enabled the fortigate integration and am sending logs on UDP 9004 using rfc5424 and per this post have followed the advice: #11995 (comment). tcpdump:
I do see this in the logs for logstash but it does not look related:
These logs were working perfectly on SO 2.3.x but had to re-install from scratch to get to 2.4 and since then these Fortigate logs have never worked. Not sure what to check next but really need to get these logs processed. Please advise Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 3 comments 11 replies
-
check this same problem for me and it is resolved |
Beta Was this translation helpful? Give feedback.
-
Still having problems with this one and have resorted to syslog on port 514 as that way the logs are at least arriving and are searchable. I have spent way to long on this integration and would be happy to parse out the logs in kv format to make them searchable. I have tried a custom parser and put it in /opt/so/saltstack/local/salt/elasticsearch/files/ingest and it never started up a listener. Here is what I have in the file I created:
After 2 months I need to get this sorted out so the logs are searchable and not just one big message field. Can someone help me with this??? |
Beta Was this translation helpful? Give feedback.
-
Can you screen shot the result of the following commands:
|
Beta Was this translation helpful? Give feedback.
Base on that screenshot it looks like the the Elastic Fleet integration is missing or misconfigured. Since your we use both "Standalone" install type you should tweak "so-grid-nodes_general"
#12055