I have a FortiGate 200E firewall and I can see the logs reaching the filebeat machine (using tcpdump listening on port 9004). but filebeat doesn't process them ( no logs in discover tab the output of
journalctl -xeu filebeat | grep forti is empty).
Fortinet module is enabled and other filebeat modules are working correctly.
ELK version is 7.8