# Fortinet module fails to install

**URL:** <https://discuss.elastic.co/t/fortinet-module-fails-to-install/284777>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 21, 2021, 11:08pm UTC](https://discuss.elastic.co/t/fortinet-module-fails-to-install/284777 "2021-09-21T23:08:48Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gorillabiscuit](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gorillabiscuit/32/94879_2.png) [@Gorillabiscuit](https://discuss.elastic.co/u/Gorillabiscuit)\
**Post date:** [September 21, 2021, 11:08pm UTC](https://discuss.elastic.co/t/fortinet-module-fails-to-install/284777/1 "2021-09-21T23:08:48Z")

</div>

I inherited an ELK stack and recently upgraded my firewall. We can send syslog to filebeat, which I'm doing, and then filebeat should be sending to ES. When I try and run the filebeat setup -e from the remote server I get errors. I worked through them and got to this point of almost success:

```auto
Loading dashboards (Kibana must be running and reachable)
2021-09-21T23:00:55.054Z INFO kibana/client.go:119 Kibana url: http://10.10.10.245:5601
2021-09-21T23:00:57.264Z INFO kibana/client.go:119 Kibana url: http://10.10.10.245:5601
2021-09-21T23:02:14.785Z ERROR instance/beat.go:971 Exiting: Failed to import dashboard: Failed to load directory /usr/share/filebeat/kibana/7/dashboard:
  error loading /usr/share/filebeat/kibana/7/dashboard/Filebeat-nats-overview.json: returned 500 to import file: <nil>. Response: {"statusCode":500,"error":"Internal Server Error","message":"An internal server error occurred."}
  error loading /usr/share/filebeat/kibana/7/dashboard/Filebeat-threatintel-abuse-url.json: returned 500 to import file: <nil>. Response: {"statusCode":500,"error":"Internal Server Error","message":"An internal server error occurred."}
  error loading /usr/share/filebeat/kibana/7/dashboard/Filebeat-threatintel-alienvault-otx.json: returned 500 to import file: <nil>. Response: {"statusCode":500,"error":"Internal Server Error","message":"An internal server error occurred."}
  error loading /usr/share/filebeat/kibana/7/dashboard/Filebeat-threatintel-anomali.json: returned 500 to import file: <nil>. Response: {"statusCode":500,"error":"Internal Server Error","message":"An internal server error occurred."}
  error loading /usr/share/filebeat/kibana/7/dashboard/Filebeat-threatintel-aubse-malware.json: returned 500 to import file: <nil>. Response: {"statusCode":500,"error":"Internal Server Error","message":"An internal server error occurred."}
  error loading /usr/share/filebeat/kibana/7/dashboard/Filebeat-threatintel-misp.json: returned 500 to import file: <nil>. Response: {"statusCode":500,"error":"Internal Server Error","message":"An internal server error occurred."}
  error loading /usr/share/filebeat/kibana/7/dashboard/Filebeat-threatintel-overview.json: returned 500 to import file: <nil>. Response: {"statusCode":500,"error":"Internal Server Error","message":"An internal server error occurred."}
Exiting: Failed to import dashboard: Failed to load directory /usr/share/filebeat/kibana/7/dashboard:
  error loading /usr/share/filebeat/kibana/7/dashboard/Filebeat-nats-overview.json: returned 500 to import file: <nil>. Response: {"statusCode":500,"error":"Internal Server Error","message":"An internal server error occurred."}
  error loading /usr/share/filebeat/kibana/7/dashboard/Filebeat-threatintel-abuse-url.json: returned 500 to import file: <nil>. Response: {"statusCode":500,"error":"Internal Server Error","message":"An internal server error occurred."}
  error loading /usr/share/filebeat/kibana/7/dashboard/Filebeat-threatintel-alienvault-otx.json: returned 500 to import file: <nil>. Response: {"statusCode":500,"error":"Internal Server Error","message":"An internal server error occurred."}
  error loading /usr/share/filebeat/kibana/7/dashboard/Filebeat-threatintel-anomali.json: returned 500 to import file: <nil>. Response: {"statusCode":500,"error":"Internal Server Error","message":"An internal server error occurred."}
  error loading /usr/share/filebeat/kibana/7/dashboard/Filebeat-threatintel-aubse-malware.json: returned 500 to import file: <nil>. Response: {"statusCode":500,"error":"Internal Server Error","message":"An internal server error occurred."}
  error loading /usr/share/filebeat/kibana/7/dashboard/Filebeat-threatintel-misp.json: returned 500 to import file: <nil>. Response: {"statusCode":500,"error":"Internal Server Error","message":"An internal server error occurred."}
  error loading /usr/share/filebeat/kibana/7/dashboard/Filebeat-threatintel-overview.json: returned 500 to import file: <nil>. Response: {"statusCode":500,"error":"Internal Server Error","message":"An internal server error occurred."}

```

Can someone help? I feel like I'm just missing something silly.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 21, 2021, 11:52pm UTC](https://discuss.elastic.co/t/fortinet-module-fails-to-install/284777/2 "2021-09-21T23:52:38Z")

</div>

Welcome to our community! 😃

Can you check your Kibana and Elasticsearch logs for anything at that time?

---

<div class="post-metadata">

**Author:** ![Gorillabiscuit](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gorillabiscuit/32/94879_2.png) [@Gorillabiscuit](https://discuss.elastic.co/u/Gorillabiscuit)\
**Post date:** [September 22, 2021, 1:17pm UTC](https://discuss.elastic.co/t/fortinet-module-fails-to-install/284777/3 "2021-09-22T13:17:14Z")

</div>

Thanks Mark! I checked for anything error-wise in kibana and I didn't see anything that lined up. Kibana logs to the default syslog, and I didn't see anything. Elastic seems to not be logging, as the Elasticsearch.log only returns up to the end of last year so I'm not sure what's going on.

I did notice that filebeat is disabled on ELK as well, in case that helps.

---

<div class="post-metadata">

**Author:** ![Gorillabiscuit](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gorillabiscuit/32/94879_2.png) [@Gorillabiscuit](https://discuss.elastic.co/u/Gorillabiscuit)\
**Post date:** [September 23, 2021, 2:50pm UTC](https://discuss.elastic.co/t/fortinet-module-fails-to-install/284777/4 "2021-09-23T14:50:17Z")

</div>

So the logs are there, named my cluster name. lol, learning as I go! I see this error in my kibana logs relevant to the time I just ran filebeat setup -e.

```auto
"tags":["debug","plugins","usageCollection","collector-set"],"pid":16495,"message":"not sending [kibana_settings] monitoring document because [undefined] is null or invalid."}

```

One question is do I have to run the filebeat setup -e locally on ES or can I do it with a remote server configured in filebeat? I can't get filebeat to run on ELK.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 27, 2021, 12:17am UTC](https://discuss.elastic.co/t/fortinet-module-fails-to-install/284777/5 "2021-09-27T00:17:50Z")

</div>

You can run setup from any Filebeat instance.

---

<div class="post-metadata">

**Author:** ![Gorillabiscuit](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gorillabiscuit/32/94879_2.png) [@Gorillabiscuit](https://discuss.elastic.co/u/Gorillabiscuit)\
**Post date:** [September 27, 2021, 12:22pm UTC](https://discuss.elastic.co/t/fortinet-module-fails-to-install/284777/6 "2021-09-27T12:22:48Z")

</div>

Thanks. I followed some instructions online on how to get a secondary admin setup and that worked fine. I can now authenticate via X-Pack local file creds for accessing ES via CURL and validating access. I continue to get this error:

```auto
2021-09-27T12:20:09.226Z ERROR instance/beat.go:971 Exiting: Failed to import dashboard: Failed to load directory /usr/share/fi lebeat/kibana/7/dashboard:
  error loading /usr/share/filebeat/kibana/7/dashboard/Filebeat-nats-overview.json: returned 500 to import file: <nil>. Response: {"statusC ode":500,"error":"Internal Server Error","message":"An internal server error occurred."}
  error loading /usr/share/filebeat/kibana/7/dashboard/Filebeat-threatintel-abuse-url.json: returned 500 to import file: <nil>. Response: { "statusCode":500,"error":"Internal Server Error","message":"An internal server error occurred."}
  error loading /usr/share/filebeat/kibana/7/dashboard/Filebeat-threatintel-alienvault-otx.json: returned 500 to import file: <nil>. Respon se: {"statusCode":500,"error":"Internal Server Error","message":"An internal server error occurred."}
  error loading /usr/share/filebeat/kibana/7/dashboard/Filebeat-threatintel-anomali.json: returned 500 to import file: <nil>. Response: {"s tatusCode":500,"error":"Internal Server Error","message":"An internal server error occurred."}
  error loading /usr/share/filebeat/kibana/7/dashboard/Filebeat-threatintel-aubse-malware.json: returned 500 to import file: <nil>. Respons e: {"statusCode":500,"error":"Internal Server Error","message":"An internal server error occurred."}
  error loading /usr/share/filebeat/kibana/7/dashboard/Filebeat-threatintel-misp.json: returned 500 to import file: <nil>. Response: {"stat usCode":500,"error":"Internal Server Error","message":"An internal server error occurred."}
  error loading /usr/share/filebeat/kibana/7/dashboard/Filebeat-threatintel-overview.json: returned 500 to import file: <nil>. Response: {" statusCode":500,"error":"Internal Server Error","message":"An internal server error occurred."}
Exiting: Failed to import dashboard: Failed to load directory /usr/share/filebeat/kibana/7/dashboard:
  error loading /usr/share/filebeat/kibana/7/dashboard/Filebeat-nats-overview.json: returned 500 to import file: <nil>. Response: {"statusC ode":500,"error":"Internal Server Error","message":"An internal server error occurred."}
  error loading /usr/share/filebeat/kibana/7/dashboard/Filebeat-threatintel-abuse-url.json: returned 500 to import file: <nil>. Response: { "statusCode":500,"error":"Internal Server Error","message":"An internal server error occurred."}
  error loading /usr/share/filebeat/kibana/7/dashboard/Filebeat-threatintel-alienvault-otx.json: returned 500 to import file: <nil>. Respon se: {"statusCode":500,"error":"Internal Server Error","message":"An internal server error occurred."}
  error loading /usr/share/filebeat/kibana/7/dashboard/Filebeat-threatintel-anomali.json: returned 500 to import file: <nil>. Response: {"s tatusCode":500,"error":"Internal Server Error","message":"An internal server error occurred."}
  error loading /usr/share/filebeat/kibana/7/dashboard/Filebeat-threatintel-aubse-malware.json: returned 500 to import file: <nil>. Respons e: {"statusCode":500,"error":"Internal Server Error","message":"An internal server error occurred."}
  error loading /usr/share/filebeat/kibana/7/dashboard/Filebeat-threatintel-misp.json: returned 500 to import file: <nil>. Response: {"stat usCode":500,"error":"Internal Server Error","message":"An internal server error occurred."}
  error loading /usr/share/filebeat/kibana/7/dashboard/Filebeat-threatintel-overview.json: returned 500 to import file: <nil>. Response: {" statusCode":500,"error":"Internal Server Error","message":"An internal server error occurred."}

```

Not sure if there's anything else to do or if I'm just stuck at this point.

---

<div class="post-metadata">

**Author:** ![Gorillabiscuit](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gorillabiscuit/32/94879_2.png) [@Gorillabiscuit](https://discuss.elastic.co/u/Gorillabiscuit)\
**Post date:** [September 28, 2021, 8:58pm UTC](https://discuss.elastic.co/t/fortinet-module-fails-to-install/284777/7 "2021-09-28T20:58:18Z")

</div>

OK, Update. I was able to get the module to install, enable, and I'm no longer getting filebeat errors, When I run filebeat setup -e to create the fortinet indices, I get this error now:

```auto
 filebeat[80319]: Exiting: Error reading fileset fortinet/firewall: Variable internal_interfaces doesn't have a 'default' key

```

I'm so close I can taste it. I have logs successfully being sent but the shards are failing until I can get the indices added.

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [September 29, 2021, 4:05am UTC](https://discuss.elastic.co/t/fortinet-module-fails-to-install/284777/8 "2021-09-29T04:05:52Z")

</div>

It's because `var.internal_interfaces` doesn't have a value. Your need to set something since there isn't a default. What's weird is it shouldn't need a value as it will just not set the config that depends on it so idk why it's complaining. What version are u using?

---

<div class="post-metadata">

**Author:** ![Gorillabiscuit](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gorillabiscuit/32/94879_2.png) [@Gorillabiscuit](https://discuss.elastic.co/u/Gorillabiscuit)\
**Post date:** [September 29, 2021, 7:22pm UTC](https://discuss.elastic.co/t/fortinet-module-fails-to-install/284777/9 "2021-09-29T19:22:58Z")

</div>

So I think I got the indexes loaded for the FG module. I'm actually running it successfully from another filebeat agent. At this point I'm seeing the fortinet filters in Kibana. I still have 2 shards from the syslogger that are still showing an illegal exception. I've restarted the service and will monitor. Thanks for your assistance @legoguy1000

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 27, 2021, 9:23pm UTC](https://discuss.elastic.co/t/fortinet-module-fails-to-install/284777/10 "2021-10-27T21:23:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
