# Adding fortinet FortiGate firewall as agent to fleet

**URL:** <https://discuss.elastic.co/t/adding-fortinet-fortigate-firewall-as-agent-to-fleet/320362>\
**Category:** Elastic Agent\
**Tags:** integrations\
**Created:** [December 2, 2022, 11:22am UTC](https://discuss.elastic.co/t/adding-fortinet-fortigate-firewall-as-agent-to-fleet/320362 "2022-12-02T11:22:31Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Med2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/med2/32/101718_2.png) [@Med2](https://discuss.elastic.co/u/Med2)\
**Post date:** [December 2, 2022, 11:22am UTC](https://discuss.elastic.co/t/adding-fortinet-fortigate-firewall-as-agent-to-fleet/320362/1 "2022-12-02T11:22:31Z")

</div>

Hi,

I've installed an elastic agent server and added to it several windows machines and linux servers using the enrollment tokens.

Now that I've added the "Fortinet FortiGate Firewall Logs" integration in kibana and after configuring Fortinet to send syslog logs to the Elastic Agent address I wasn't able to receive any logs.

When adding an agent in kibana you're given a set of commands relative to the OS as well as an enrollment token to use when installing elastic agent on an endpoint but I'm not sure how that can be configured on Fortigate.

Thanks

---

<div class="post-metadata">

**Author:** ![hendry.lim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendry.lim/32/71328_2.png) [@hendry.lim](https://discuss.elastic.co/u/hendry.lim)\
**Post date:** [December 2, 2022, 12:24pm UTC](https://discuss.elastic.co/t/adding-fortinet-fortigate-firewall-as-agent-to-fleet/320362/2 "2022-12-02T12:24:06Z")

</div>

The Elastic Agent enrollment command should only be used to enroll the agent. Once you have got the agent enrolled into Fleet, you should be able to add other integrations to the same agent policy.

You may want to make sure that your agent has been enrolled successfully with Fleet and it's using the correct agent policy that you have added the Fortinet integration to.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [December 2, 2022, 12:37pm UTC](https://discuss.elastic.co/t/adding-fortinet-fortigate-firewall-as-agent-to-fleet/320362/3 "2022-12-02T12:37:01Z")

</div>

> [@Med2](#):
>
> Fortinet to send syslog logs to the Elastic Agent address I wasn't able to receive any logs.

Did you check if this isn't a network issue like a firewall or something?

---

<div class="post-metadata">

**Author:** ![Med2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/med2/32/101718_2.png) [@Med2](https://discuss.elastic.co/u/Med2)\
**Post date:** [December 2, 2022, 2:17pm UTC](https://discuss.elastic.co/t/adding-fortinet-fortigate-firewall-as-agent-to-fleet/320362/4 "2022-12-02T14:17:04Z")

</div>

The problem I'm facing is how to enroll a firewall into fleet, there are commands on how to do so for Linux. Windows, RPM, Debian..etc but not for firewalls and routers.

---

<div class="post-metadata">

**Author:** ![hendry.lim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendry.lim/32/71328_2.png) [@hendry.lim](https://discuss.elastic.co/u/hendry.lim)\
**Post date:** [December 2, 2022, 2:38pm UTC](https://discuss.elastic.co/t/adding-fortinet-fortigate-firewall-as-agent-to-fleet/320362/5 "2022-12-02T14:38:36Z")

</div>

You can't install the agent in your routers/firewalls. You should configure your routers/firewalls to send syslog through UDP/TCP to your Elastic Agent hosted in a Linux/Windows host.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 30, 2022, 2:39pm UTC](https://discuss.elastic.co/t/adding-fortinet-fortigate-firewall-as-agent-to-fleet/320362/6 "2022-12-30T14:39:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
