We are monitoring our Fortinet firewalls using Elasticsearch, Filebeat, and Kibana. But the traffic volume shown by the firewall's in-built dashboard is different from the traffic volume aggregated by Elasticsearch and Kibana. As per documentation, the field of traffic volume is directed to Network.bytes in the ECS field.
Please suggest what i can do to match the exact result.
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.