Hi to all
I can't figure out why the Fortigate Firewall Logs Integration doesn't send logs to my Elasticsearch server
I can use the filebeat module but not the fleet integration
I have setup the Fortigate Firewall to send syslog log to my syslog server
The last one is a Ubuntu Server machine with Elastic-Agent installed and configured as fleet agent
With tcpdump I see the raw record that firewall sends to syslogserver
If I run the command netstat -ln, I see that the server is listening on port 9004
I also tried to stop the elastic-agent service and the open port disappeared
In the elastic-agent log, I can't see any error
Are you using the TCP input for this? Remember to disable the ones you are not using when in the integration configuration UI.
If you are using TCP, try to open the advance option section, under TCP options there is a field commented out called framing
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.