# Fortigate Integrations

**URL:** https://discuss.elastic.co/t/fortigate-integrations/366211
**Category:** SIEM
**Created:** [September 8, 2024, 6:22pm UTC](https://discuss.elastic.co/t/fortigate-integrations/366211 "2024-09-08T18:22:02Z")
**Posts on this page:** 1
**Showing post:** 5

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [September 8, 2024, 10:00pm UTC](https://discuss.elastic.co/t/fortigate-integrations/366211/5 "2024-09-08T22:00:54Z")

</div>

First please do not post images of text... please paste the text and formate with with 2 backticks ````` before and after ...images can not be searched debugged etc.. some people can not see them.

This

> [@arcsons](#):
>
> .ds-logs-fortinet\_fortigate.log-default-2024.09.08-000001  
> Health: Yellow  
> Status: Open

and this show you are ingesting data....

> [@arcsons](#):
>
> GET logs-fortinet\_fortigate.log-\*/\_search  
> shows me 200 OK and some interesting stuff but not all.

When I ask for this please provide some of the sample results... not just "Some interesting stuff" otherwise I can not help...

Please post a few of those results...

You probably have a timezone issue... please see this post...

> [@Elastic Search have index file and i can add it to Kibana but is said no data](https://discuss.elastic.co/t/elastic-search-have-index-file-and-i-can-add-it-to-kibana-but-is-said-no-data/365862/7):
>
> @D_Nang_Kien Please do not share text as screen shots it is very hard to work with... Most likely, you are writing data without a timezone, so the data is in the "future" ... you will need to account for that All Data is stored in UTC in Elastic. If you send data from your timezone and do not provide the timezone the data will be captured and stored as UTC... What timezone are you in? Rerun the generator. Go to the Time Picker...and set exactly this and show me what you see.... and set t…

Set the time picker in Discover to 24 hours ago to 24 hours to now... and see if you have results... I am sure you do.

######################################

The other logs error logs...

What are you doing with logstash?... this is why do not paste image of text... I can not help much... This is probably not the issue with the fortigate logs... but whatever you are doing with logstasth it is trying to connect to Elasticsearch at the default address... `http://localhost:9200` which above is probably not correct...

 ![Screenshot 2024-09-08 at 2.54.19 PM](https://us1.discourse-cdn.com/elastic/original/3X/3/c/3c1fba7b3786ae71fb9b1ebdcb0e6f491d653c6b.png)

I would think you are trying to do

Fortigate -\> UDP Elastic Agent -\> Elasticsearch

Or are you trying

Fortigate -\> UDP Elastic Agent -\> Logstash -\> Elasticsearch

If so why?

---

_[View the full topic](https://discuss.elastic.co/t/fortigate-integrations/366211)._
