# Filebeat not sending logs to elastic from fortinet module

**URL:** <https://discuss.elastic.co/t/filebeat-not-sending-logs-to-elastic-from-fortinet-module/254000>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 2, 2020, 9:24am UTC](https://discuss.elastic.co/t/filebeat-not-sending-logs-to-elastic-from-fortinet-module/254000 "2020-11-02T09:24:15Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![mn0o7](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mn0o7/32/78259_2.png) [@mn0o7](https://discuss.elastic.co/u/mn0o7)\
**Post date:** [November 2, 2020, 9:24am UTC](https://discuss.elastic.co/t/filebeat-not-sending-logs-to-elastic-from-fortinet-module/254000/1 "2020-11-02T09:24:15Z")

</div>

Hi Everyone,

I have enabled the fortinet/firewall module all looks great i see traffic being received at in the filebeat logs but never forwarded to elastic, can someone please point me in the right direction ?

filebeat.yml config:

logging.to\_stder: true  
logging.level: debug  
setup.template.name: "logs\_k8s"  
setup.template.pattern: "logs\_\*"

filebeat.modules:

- module: fortinet  
firewall:  
enabled: true  
var.input: tcp  
var.syslog\_host: "0.0.0.0"  
var.syslog\_port: 9004  
setup.ilm.enabled: false  
ilm.enabled: false  
logging.metrics.enabled: false  
output.elasticsearch:  
enabled: true  
index: "logs\_forti"  
hosts: ['localhost:9200']

## fortinet.yml

filebeat.modules:

- module: fortinet  
firewall:  
enabled: true  
var.input: tcp  
var.syslog\_host: "0.0.0.0"  
var.syslog\_port: 9004

2020-11-02T09:05:40.204Z INFO instance/beat.go:647 Home path: [/usr/share/filebeat] Config path: [//filebeat/logs]  
2020-11-02T09:05:40.204Z DEBUG [beat] instance/beat.go:699 Beat metadata path: /usr/share/filebeat/  
2020-11-02T09:05:40.204Z INFO instance/beat.go:655 Beat ID: 76a6ab0b-7cbb-4948-8881-bbd9ce0f4d3e  
2020-11-02T09:05:40.204Z DEBUG [seccomp] seccomp/seccomp.go:117 Loading syscall filter {"seccom","syscalls":[{"names":["accept","accept4","access","arch\_prctl","bind","brk","chmod","chown","clock\_gettime","c"epoll\_pwait","epoll\_wait","exit","exit\_group","fchdir","fchmod","fchmodat","fchown","fchownat","fcntl","fdatasyetdents64","geteuid","getgid","getpeername","getpid","getppid","getrandom","getrlimit","getrusage","getsockname"1","inotify\_rm\_watch","ioctl","kill","listen","lseek","lstat","madvise","mincore","mkdirat","mmap","mprotect","mread64","pselect6","pwrite64","read","readlink","readlinkat","recvfrom","recvmmsg","recvmsg","rename","renameat"","sendfile","sendmmsg","sendmsg","sendto","set\_robust\_list","setitimer","setsockopt","shutdown","sigaltstack","nk","unlinkat","wait4","waitid","write","writev"],"action":"allow"}]}}}  
2020-11-02T09:05:40.204Z INFO [seccomp] seccomp/seccomp.go:124 Syscall filter successfully inst  
2020-11-02T09:05:40.205Z INFO [beat] instance/beat.go:983 Beat info {"system\_info": {"beat":"home": "/usr/share/filebeat", "logs": "/usr/share/filebeat/logs"}, "type": "filebeat", "uuid": "76a6ab0b-7cbb-4  
2020-11-02T09:05:40.205Z INFO [beat] instance/beat.go:992 Build info {"system\_info": {"build"me": "2020-07-21T15:12:45.000Z", "version": "7.8.1"}}}  
2020-11-02T09:05:40.206Z INFO [beat] instance/beat.go:995 Go runtime info {"system\_info": {"go": {  
2020-11-02T09:05:40.206Z INFO [beat] instance/beat.go:999 Host info {"system\_info": {"host":e,"name":"21df9483e813","ip":["127.0.0.1/8","172.17.0.2/16"],"kernel\_version":"5.3.0-1032-aws","mac":["02:42:ac:rsion":"7 (Core)","major":7,"minor":8,"patch":2003,"codename":"Core"},"timezone":"UTC","timezone\_offset\_sec":0,"  
2020-11-02T09:05:40.207Z INFO [beat] instance/beat.go:1028 Process info {"system\_info": {"procesill","setgid","setuid","setpcap","net\_bind\_service","net\_raw","sys\_chroot","mknod","audit\_write","setfcap"],"percap","net\_bind\_service","net\_raw","sys\_chroot","mknod","audit\_write","setfcap"],"effective":["chown","dac\_overri\_raw","sys\_chroot","mknod","audit\_write","setfcap"],"bounding":["chown","dac\_override","fowner","fsetid","kill",udit\_write","setfcap"],"ambient":null}, "cwd": "/usr/share/filebeat", "exe": "/usr/share/filebeat/filebeat", "na:true}, "start\_time": "2020-11-02T09:05:38.860Z"}}}  
2020-11-02T09:05:40.207Z INFO instance/beat.go:310 Setup Beat: filebeat; Version: 7.8.1  
2020-11-02T09:05:40.207Z DEBUG [beat] instance/beat.go:336 Initializing output plugins  
2020-11-02T09:05:40.207Z INFO eslegclient/connection.go:99 elasticsearch url: [http://localhost:9200](http://localhost:9200)  
2020-11-02T09:05:40.208Z DEBUG [publisher] pipeline/consumer.go:137 start pipeline event con  
2020-11-02T09:05:40.208Z INFO [publisher] pipeline/module.go:113 Beat name: 21df9483e813  
2020-11-02T09:05:40.213Z INFO beater/filebeat.go:96 Enabled modules/filesets: fortinet (firewall),  
2020-11-02T09:05:40.214Z INFO instance/beat.go:463 filebeat start running.  
2020-11-02T09:05:40.214Z DEBUG [test] registrar/migrate.go:159 isFile(/usr/share/filebeat/data/  
2020-11-02T09:05:40.214Z DEBUG [test] registrar/migrate.go:159 isFile() -\> false  
2020-11-02T09:05:40.214Z DEBUG [test] registrar/migrate.go:152 isDir(/usr/share/filebeat/data/r  
2020-11-02T09:05:40.214Z DEBUG [test] registrar/migrate.go:159 isFile(/usr/share/filebeat/data/  
2020-11-02T09:05:40.214Z DEBUG [registrar] registrar/migrate.go:51 Registry type '0' found  
2020-11-02T09:05:40.215Z DEBUG [registrar] registrar/registrar.go:125 Registry file set to: /u  
2020-11-02T09:05:40.215Z INFO registrar/registrar.go:145 Loading registrar data from /usr/share/f  
2020-11-02T09:05:40.215Z INFO registrar/registrar.go:152 States Loaded from registrar: 0  
2020-11-02T09:05:40.215Z INFO [crawler] beater/crawler.go:71 Loading Inputs: 1  
2020-11-02T09:05:40.215Z DEBUG [registrar] registrar/registrar.go:278 Starting Registrar  
2020-11-02T09:05:40.215Z DEBUG [processors] processors/processor.go:101 Generated new processors  
2020-11-02T09:05:40.215Z INFO [crawler] beater/crawler.go:141 Starting input (ID: 155424624740  
2020-11-02T09:05:40.216Z INFO [crawler] beater/crawler.go:108 Loading and starting Inputs comp  
2020-11-02T09:05:40.216Z INFO [input.tcp] tcp/input.go:110 Starting TCP input {"addres  
2020-11-02T09:05:40.220Z INFO [tcp] common/listener.go:89 Started listening for TCP connection  
2020-11-02T09:05:44.190Z DEBUG [tcp] common/listener.go:132 New client {"address": "0.0.0.0:900  
2020-11-02T09:05:50.220Z DEBUG [input] input/input.go:141 Run input  
2020-11-02T09:06:00.221Z DEBUG [input] input/input.go:141 Run input  
2020-11-02T09:06:10.221Z DEBUG [input] input/input.go:141 Run input

---

<div class="post-metadata">

**Author:** ![mn0o7](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mn0o7/32/78259_2.png) [@mn0o7](https://discuss.elastic.co/u/mn0o7)\
**Post date:** [November 3, 2020, 8:15am UTC](https://discuss.elastic.co/t/filebeat-not-sending-logs-to-elastic-from-fortinet-module/254000/2 "2020-11-03T08:15:35Z")

</div>

Never mind the forti was faking sending the syslog messages

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 1, 2020, 10:15am UTC](https://discuss.elastic.co/t/filebeat-not-sending-logs-to-elastic-from-fortinet-module/254000/3 "2020-12-01T10:15:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
