# Fortigate Firewall Logs to Elasticsearch

**URL:** <https://discuss.elastic.co/t/fortigate-firewall-logs-to-elasticsearch/294041>\
**Category:** Logstash\
**Created:** [January 11, 2022, 2:05pm UTC](https://discuss.elastic.co/t/fortigate-firewall-logs-to-elasticsearch/294041 "2022-01-11T14:05:52Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![yogicd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yogicd/32/93629_2.png) [@yogicd](https://discuss.elastic.co/u/yogicd)\
**Post date:** [January 11, 2022, 2:05pm UTC](https://discuss.elastic.co/t/fortigate-firewall-logs-to-elasticsearch/294041/1 "2022-01-11T14:05:52Z")

</div>

Hi Team,  
I am trying to get the Fortigate firewall logs to elasticsearch via logstash but not able to get the data to elasticsearch, But i can see the data coming via tcpdump udp port 514.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/2/320d2985d0e5186709f066f7b585e9a0fe5c27d2.png)

and my logstash config as below

# Sample Logstash configuration for creating a simple

# Beats -\> Logstash -\> Elasticsearch pipeline.

input {  
stdin {}  
beats {  
port =\> 514  
}  
}

output {  
elasticsearch {  
hosts =\> ["[http://192.168.0.60:9204](http://192.168.0.60:9204)"]  
manage\_template =\> false  
index =\> "%{[@metadata][fortigate]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
#user =\> "elastic"  
#password =\> "changeme"  
}  
stdout { codec =\> rubydebug }  
}

Presently not filtering the data presently and is it possible to get the output to CSV file .  
Using version Elasticsearch7.14,kibana 7.14,logstash7.14,filebeat 7.14

Thanks

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 11, 2022, 2:14pm UTC](https://discuss.elastic.co/t/fortigate-firewall-logs-to-elasticsearch/294041/2 "2022-01-11T14:14:26Z")

</div>

You have two issues, one is that the `beats` input is to be used with the beats agents, filebeat, metricbeat etc, if you send anything that is not using the beats protocol to a beats input, it will be dropped in the input and will log an error or warn.

So, you need to change the `beats` input for the `udp` input, this way your logstash will be able to receive data using `udp`.

Just use:

```auto
input {
    udp {
        port => 514
    }
}

```

The second issue is that you are using the port `514` in the input, so you are probably running logstash a root, right? This is not recommended for security reasons.

I would suggest that you change the port to a higher port, something like `5514` and reconfigure your firewall device to ship logs using this port.

---

<div class="post-metadata">

**Author:** ![yogicd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yogicd/32/93629_2.png) [@yogicd](https://discuss.elastic.co/u/yogicd)\
**Post date:** [January 11, 2022, 2:42pm UTC](https://discuss.elastic.co/t/fortigate-firewall-logs-to-elasticsearch/294041/3 "2022-01-11T14:42:53Z")

</div>

@leandrojmp Thanks! I have changed the input and port also and Now i am able to get the data to Elasticsearch.  
How to filter the log and get log output to .csv or .log file and is it possible to write the data both Elasticsearch and .csv or .log file.

Thanks  
Yogi

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 8, 2022, 2:43pm UTC](https://discuss.elastic.co/t/fortigate-firewall-logs-to-elasticsearch/294041/4 "2022-02-08T14:43:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
