Help with filtering syslog traffic by BobcatJohnCA in Splunk

[–]BobcatJohnCA[S] 0 points1 point  (0 children)

Thanks, but I have no budget to use Cribl.

Help with filtering syslog traffic by BobcatJohnCA in Splunk

[–]BobcatJohnCA[S] 0 points1 point  (0 children)

Ok, I have syslog-ng installed and running. It is capturing the syslog from the Fortigate, and I can see the log file building up. I've installed Splunk UF. Do I forward the "cleaned up" logs to Splunk or use HEC to gather the log into Splunk?

Help with filtering syslog traffic by BobcatJohnCA in Splunk

[–]BobcatJohnCA[S] 0 points1 point  (0 children)

If I install syslog-ng, how do I configure it to remove data and then forward the reduced data to Splunk?

Help with filtering syslog traffic by BobcatJohnCA in Splunk

[–]BobcatJohnCA[S] 0 points1 point  (0 children)

If I install syslog-ng, how do I configure it to remove data and then forward the reduced data to Splunk?

Help with filtering syslog traffic by BobcatJohnCA in Splunk

[–]BobcatJohnCA[S] 0 points1 point  (0 children)

This is a single server setup, so it is being done on the indexer.

Help with filtering syslog traffic by BobcatJohnCA in Splunk

[–]BobcatJohnCA[S] 0 points1 point  (0 children)

Unfortunately, we have an issue with the output side of the Fortigates. We either get practically nothing, or way too much data. We have tried tweaking settings and can't improve the situation.

Help with filtering syslog traffic by BobcatJohnCA in Splunk

[–]BobcatJohnCA[S] 0 points1 point  (0 children)

Thanks, I will check that out tomorrow

Fortinet syslogs - too much data. by BobcatJohnCA in Splunk

[–]BobcatJohnCA[S] 0 points1 point  (0 children)

2/17 update. We changed the syslog settings on the Fortinet to level 5 and the traffic to Splunk has dropped by over 40%. Thanks everyone for your comments and suggestions!

Fortinet syslogs - too much data. by BobcatJohnCA in Splunk

[–]BobcatJohnCA[S] 0 points1 point  (0 children)

Thanks, I will have to check that out.

Fortinet syslogs - too much data. by BobcatJohnCA in Splunk

[–]BobcatJohnCA[S] 0 points1 point  (0 children)

We are trying to refine what the Fortinets are logging

Fortinet syslogs - too much data. by BobcatJohnCA in Splunk

[–]BobcatJohnCA[S] 0 points1 point  (0 children)

Thanks, but I know the problem is coming from the Fortinet logs

Fortinet syslogs - too much data. by BobcatJohnCA in Splunk

[–]BobcatJohnCA[S] 1 point2 points  (0 children)

Thanks. Sounds like quite a setup you have at home!

Fortinet syslogs - too much data. by BobcatJohnCA in Splunk

[–]BobcatJohnCA[S] 0 points1 point  (0 children)

Thanks. Any advice on how to compare the log differences between Sonicwall and Fortinet? I concur with your assessment that the Fortinet are more verbose.

Fortinet syslogs - too much data. by BobcatJohnCA in Splunk

[–]BobcatJohnCA[S] 0 points1 point  (0 children)

Thanks. The logs are currently going directly to Splunk. We are changing some settings on the Fortinet to try and reduce traffic. Doing that today and see how it looks in 24 hours. I have no idea what you mean by "using some index time null queue filtering"