These are different things, when using pipelines.yml you will have both pipelines running.
Logstash will always have a queue, but this queue can be a memory queue, the default, or a persistent disk queue, as you configured it for the fortinet pipeline.
The queue is not an issue as it will always exist, if you are not receiving any logs for the fortinet pipeline you need to troubleshoot it.
First do you have any log error in Logstash? How does the /etc/logstash/conf.d/forti.conf looks like?
Also, use tcpdump on the server to check if you are indeed receiving logs from your network device, this is the first thing you need to check.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.