# Filebeat Fortinet module not working

**URL:** https://discuss.elastic.co/t/filebeat-fortinet-module-not-working/247063
**Category:** Beats
**Tags:** beats-module, filebeat
**Created:** [September 1, 2020, 8:51am UTC](https://discuss.elastic.co/t/filebeat-fortinet-module-not-working/247063 "2020-09-01T08:51:35Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![bornatalebi](https://avatars.discourse-cdn.com/v4/letter/b/e68b1a/32.png) [@bornatalebi](https://discuss.elastic.co/u/bornatalebi)
#### Post date: [September 1, 2020, 8:51am UTC](https://discuss.elastic.co/t/filebeat-fortinet-module-not-working/247063/1 "2020-09-01T08:51:35Z")

</div>

I have a FortiGate 200E firewall and I can see the logs reaching the filebeat machine (using tcpdump listening on port 9004). but filebeat doesn't process them ( no logs in discover tab the output of `journalctl -xeu filebeat | grep forti` is empty).

Fortinet module is enabled and other filebeat modules are working correctly.

ELK version is 7.8

---

<div class="post-metadata">

### Author: ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)
#### Post date: [September 1, 2020, 9:37am UTC](https://discuss.elastic.co/t/filebeat-fortinet-module-not-working/247063/2 "2020-09-01T09:37:27Z")

</div>

Hi!

Could you run Filebeat in debug mode ([https://www.elastic.co/guide/en/beats/filebeat/current/enable-filebeat-debugging.html](https://www.elastic.co/guide/en/beats/filebeat/current/enable-filebeat-debugging.html)) and check if there is anything interesting in the logs?

C.

---

<div class="post-metadata">

### Author: ![bornatalebi](https://avatars.discourse-cdn.com/v4/letter/b/e68b1a/32.png) [@bornatalebi](https://discuss.elastic.co/u/bornatalebi)
#### Post date: [September 1, 2020, 9:47am UTC](https://discuss.elastic.co/t/filebeat-fortinet-module-not-working/247063/3 "2020-09-01T09:47:31Z")

</div>

So something weird happened. after restarting filebeat service the logs are now processing but when i want to see them in discover tab the timestamp is +4:30, same as my timezone. if i change time range to "5 hours from now" i can see them in discover tab. if i query logs via API the timestamp is correct.  
should i open a new topic for it?

---

<div class="post-metadata">

### Author: ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)
#### Post date: [September 1, 2020, 9:51am UTC](https://discuss.elastic.co/t/filebeat-fortinet-module-not-working/247063/4 "2020-09-01T09:51:15Z")

</div>

We can open a new topic yes for better context awareness.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [October 23, 2020, 11:50am UTC](https://discuss.elastic.co/t/filebeat-fortinet-module-not-working/247063/6 "2020-10-23T11:50:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
