# Fortigate Integration - Separation of logs datastream based on a field value

**URL:** <https://discuss.elastic.co/t/fortigate-integration-separation-of-logs-datastream-based-on-a-field-value/380767>\
**Category:** Elastic Agent\
**Tags:** integrations\
**Created:** [August 5, 2025, 4:48pm UTC](https://discuss.elastic.co/t/fortigate-integration-separation-of-logs-datastream-based-on-a-field-value/380767 "2025-08-05T16:48:16Z")\
**Posts on this page:** 1\
**Showing post:** 8

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 6, 2025, 4:42pm UTC](https://discuss.elastic.co/t/fortigate-integration-separation-of-logs-datastream-based-on-a-field-value/380767/8 "2025-08-06T16:42:43Z")

</div>

> [@Knight7](#):
>
> and it could be a permission problem : Could it be that ?

It is probably a permission issue.

The way that Elastic Agent handles permissions is pretty limited, you cannot use the `reroute` processor because the API Key generated for the integration only has permissions to write into the data streams and namespace in the configuration.

You can check this similar [post](https://discuss.elastic.co/t/firewall-logs-to-different-datastream-by-type/377211) where there is a lengthy discussion about it.

In short, per default the `reroute` processor will not work, you cannot change the namespace of a datastream as the API Key generated for the policy does not include it, you can check the agent logs and you will probably have a lot of errors about not being able to index data.

The workaround for this case would be to add an integration in the same policy that has permissions to write into `logs-*-*`, this would make the API Key used by the policy to have those same permissions and it would allow you to use the `reroute` processor, for example you could add a Custom Filestream logs integration that do not collect anything, just to have the permissions.

There was a change planned to 9.1 to allow the user to specify extra permissions on the UI, but I'm not sure if it is already active as I'm on 8.18 still.

Is this change here: [[Fleet] Add UI to add additional datastreams permissions by nchaulet · Pull Request #210935 · elastic/kibana · GitHub](https://github.com/elastic/kibana/pull/210935)

---

_[View the full topic](https://discuss.elastic.co/t/fortigate-integration-separation-of-logs-datastream-based-on-a-field-value/380767)._
