Skip to content

enotspe/fortinet-2-elasticsearch

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

714 Commits
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

FortiDragon Logo

FortiDragon

The Best Analytics Platform for Firewall Logs

Discord GitHub stars License


🎯 What is FortiDragon?

Tired of expensive SIEMs that don't understand firewall logs?

FortiDragon is a full-featured analytics platform that transforms Fortinet (FortiGate, FortiEDR, FortiMail, FortiWeb) and Palo Alto PAN-OS logs into actionable threat intelligence without breaking the bank.

After 10+ years fighting with overpriced SIEMs that treat firewall logs as an leftover checkbox in a datasheet, we built the platform we always needed.

No sampling. No filtering. Full visibility. Full behavioral analysis.

πŸ’° The Problem We Solve

Traditional SIEMs force you to choose:

  • Option A: Log everything β†’ Go bankrupt from licensing costs
  • Option B: Sample/filter logs β†’ Miss threats hiding in the gaps

We chose Option C: Build a platform optimized specifically for high-volume firewall logs using modern, cost-effective tech.

Built by security analysts, for security analysts

✨ Key Features

πŸ” Deep Ingestion

  • Full field parsing - Every field from Fortinet and Palo Alto logs, not just the "important" ones
  • ECS standardization - Translates to Elastic Common Schema
  • Rich enrichment - GeoIP, network community ID, registered domains, threat intel integration

πŸ“Š Unmatched Analytics

  • Purpose-built dashboards for threat hunting (Kibana & Grafana)
  • Behavioral analysis - Detect slow burns, lateral movement, beaconing
  • No other tool (paid or free) has this depth of firewall log analysis

πŸ› οΈ Security Engineer Friendly

  • One-script deployment for Elasticsearch components
  • Pre-configured pipelines for Vector and Elastic Agent
  • Production-ready dashboards on day one
  • No vendor lock-in - swap components as needed

πŸ—οΈ Modular Architecture

Fortinet/Palo Alto β†’ Vector/Elastic Agent β†’ Elasticsearch/Victoria Logs β†’ Kibana/Grafana

Mix and match: Every layer is swappable. Use what works for your environment.

πŸ“– Documentation

All detailed documentation has moved to our dedicated documentation site:

🎨 Dashboard Preview

Dashboard

Navigate seamlessly through traffic, UTM, and event dashboards

🌟 Why FortiDragon?

Feature Traditional SIEM FortiDragon
Cost $$$$$+ per GB Free + your infrastructure
Firewall Focus Generic checkbox Purpose-built
Full Parsing "Important fields" Every field extracted
Sampling Required for cost Log everything
Dashboards Generic Threat hunting focused
Setup Time Weeks/months Hours

🀝 Community & Support

Get Help

Support the Project

You're already saving thousands on SIEM costs. Consider giving back:

πŸ—ΊοΈ Supported Platforms

Data Sources

  • βœ… Fortinet FortiGate
  • βœ… Fortinet FortiEDR
  • βœ… Fortinet FortiMail
  • βœ… Fortinet FortiWeb / FortiAppSec
  • βœ… Palo Alto PAN-OS

Ingestion

  • βœ… Vector (recommended)
  • ⚠️ Elastic Agent (deprecated)
  • ⚠️ Logstash (deprecated)

Storage Backends

  • βœ… Victoria Logs (recommended)
  • βœ… Elasticsearch

Visualization

  • βœ… Grafana (recommended)
  • βœ… Kibana

πŸ“œ License

Apache-2.0 license - See LICENSE for details

πŸ‘₯ Authors

  • Logstash pipelines, Elasticsearch config: @hoat23 & @enotspe
  • Datasets, Kibana/Grafana dashboards, Vector pipelines, Victoria Logs: @enotspe
  • Current maintenance and development: @enotspe

About

Fortinet products logs to Elasticsearch

Resources

License

Stars

Watchers

Forks

Packages

 
 
 

Contributors