# Setting up Integrations: Fortinet

**URL:** <https://discuss.elastic.co/t/setting-up-integrations-fortinet/359251>\
**Category:** Elasticsearch\
**Created:** [May 10, 2024, 10:28am UTC](https://discuss.elastic.co/t/setting-up-integrations-fortinet/359251 "2024-05-10T10:28:32Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![riahc3](https://avatars.discourse-cdn.com/v4/letter/r/d6d6ee/32.png) [@riahc3](https://discuss.elastic.co/u/riahc3)\
**Post date:** [May 10, 2024, 10:28am UTC](https://discuss.elastic.co/t/setting-up-integrations-fortinet/359251/1 "2024-05-10T10:28:32Z")

</div>

Hello

I want to try out the integration feature but Im kind of lost.

Im gonna have my ELK stack all on one server. The reason I mention this is because there is a Fleek/Elastic Agent being talked about and Im not sure what that does.

I only want to use Elastic, Logstash and Kibana. Nothing else, unless it is required.

Could you please give me a ELI5 ?

---

<div class="post-metadata">

**Author:** ![riahc3](https://avatars.discourse-cdn.com/v4/letter/r/d6d6ee/32.png) [@riahc3](https://discuss.elastic.co/u/riahc3)\
**Post date:** [May 10, 2024, 11:38am UTC](https://discuss.elastic.co/t/setting-up-integrations-fortinet/359251/2 "2024-05-10T11:38:23Z")

</div>

I wanted to start with the Fortinet Fortigate one to start and then move on.

---

<div class="post-metadata">

**Author:** ![riahc3](https://avatars.discourse-cdn.com/v4/letter/r/d6d6ee/32.png) [@riahc3](https://discuss.elastic.co/u/riahc3)\
**Post date:** [May 14, 2024, 11:30am UTC](https://discuss.elastic.co/t/setting-up-integrations-fortinet/359251/3 "2024-05-14T11:30:15Z")

</div>

Nothing?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 14, 2024, 12:46pm UTC](https://discuss.elastic.co/t/setting-up-integrations-fortinet/359251/4 "2024-05-14T12:46:18Z")

</div>

Hello,

What is exactly your question? Did you check any documention?

> [@riahc3](#):
>
> The reason I mention this is because there is a Fleek/Elastic Agent being talked about and Im not sure what that does.

The Elastic Agent is the now recommended tool to collect logs and receive data when using Elasticsearch, it will run integrations, which are preconfigured collectors and parsers, the logs are parsed using ingest pipelines in Elasticsearch, each integration will use one or more ingest pipelines to parse the logs into ecs fields.

Fleet Server is the tool that will manage the elastic agent. Each agent is part of one agent policy, and the Fleet server is responsable into distributing those policies to the agents, the policies specifies what the agent will collect and where it will send the data.

> [@riahc3](#):
>
> I only want to use Elastic, Logstash and Kibana. Nothing else, unless it is required.

Integrations requires and Elastic Agent to receive/collect the data.

If you want to use just Logstash for that you will need to parse the logs yourself using Logstash filters, you can also configure it to use an ingest pipeline in Elasticsearch, but this is a little more advanced and I would not recommend for someone that is just starting with the stack.

---

<div class="post-metadata">

**Author:** ![riahc3](https://avatars.discourse-cdn.com/v4/letter/r/d6d6ee/32.png) [@riahc3](https://discuss.elastic.co/u/riahc3)\
**Post date:** [May 14, 2024, 1:14pm UTC](https://discuss.elastic.co/t/setting-up-integrations-fortinet/359251/5 "2024-05-14T13:14:24Z")

</div>

`What is exactly your question? Did you check any documention?`

I believe the documentation might have further confused me, so I apoligize before hand.

From what I understand, the Elastic Agent is simply a component that runs on a server BUT the documentation says only ONE can run on a server. So, if I run it on my ELK server, I can only receive logs from one place. Correct?

`The Elastic Agent is the now recommended tool to collect logs and receive data when using Elasticsearch, it will run integrations, which are preconfigured collectors and parsers, the logs are parsed using ingest pipelines in Elasticsearch, each integration will use one or more ingest pipelines to parse the logs into ecs fields.`

So I need to run the Elastic Agent and then in Kibana configure the integration? Thats the part that maybe isnt clear to me.

`Fleet Server is the tool that will manage the elastic agent. Each agent is part of one agent policy, and the Fleet server is responsable into distributing those policies to the agents, the policies specifies what the agent will collect and where it will send the data.`

Why do I need more agents? Thats another confusion.

`Integrations requires and Elastic Agent to receive/collect the data.`

OK, so I NEED the Elastic Agent. Got it.

`If you want to use just Logstash for that you will need to parse the logs yourself using Logstash filters, you can also configure it to use an ingest pipeline in Elasticsearch, but this is a little more advanced and I would not recommend for someone that is just starting with the stack.`

Yeah, Ive set up Logstash pipelines but I rather go another cleaner way.

Thank you for your comments and help

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 14, 2024, 1:31pm UTC](https://discuss.elastic.co/t/setting-up-integrations-fortinet/359251/6 "2024-05-14T13:31:08Z")

</div>

> [@riahc3](#):
>
> So, if I run it on my ELK server, I can only receive logs from one place. Correct?

No, each agent can run multiple integrations, so you can receive logs from multiple places in the same agents.

This [documentation](https://www.elastic.co/guide/en/fleet/current/fleet-overview.html) has an overview on how it works and the multiple components of it.

> [@riahc3](#):
>
> So I need to run the Elastic Agent and then in Kibana configure the integration? Thats the part that maybe isnt clear to me.

You use the Fleet UI in Kibana to create an agent policy and add the integrations you want, the Fleet Server will then deploy this configuration into your agents.

> [@riahc3](#):
>
> Why do I need more agents? Thats another confusion.

This depends on what you need to collect and what your infrastructure looks like, for example if you have multiple servers and want to collect log files from those servers, than each one will need an agent, or if you want to collect logs from s3 buckets and you have a lot of lots, you may need multiple agents to balance the load, same thing with network devices, you may need to use multiple agents to balance the load.

---

<div class="post-metadata">

**Author:** ![riahc3](https://avatars.discourse-cdn.com/v4/letter/r/d6d6ee/32.png) [@riahc3](https://discuss.elastic.co/u/riahc3)\
**Post date:** [May 14, 2024, 1:48pm UTC](https://discuss.elastic.co/t/setting-up-integrations-fortinet/359251/7 "2024-05-14T13:48:19Z")

</div>

```auto
No, each agent can run multiple integrations, so you can receive logs from multiple places in the same agents.

This [documentation](https://www.elastic.co/guide/en/fleet/current/fleet-overview.html) has an overview on how it works and the multiple components of it.

```

The how to and documentation isnt clear but if I can use only one agent on the same server....

`You use the Fleet UI in Kibana to create an agent policy and add the integrations you want, the Fleet Server will then deploy this configuration into your agents.`

Thats something I also dont get about the agent policy; I feel like it should be able to set a ILM for setting hot, warm and cold phases but I dont see it. It isnt intuitive

` This depends on what you need to collect and what your infrastructure looks like, for example if you have multiple servers and want to collect log files from those servers, than each one will need an agent`

I dont understand this, Im sorry. If I have various Windows servers, why do I need various agents? How does that work?

` same thing with network devices, you may need to use multiple agents to balance the load.`

Im going to only capture Windows servers, Linux servers, network devices, and thats it. How many agents do I need? Lets keep it simple 🙂

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 14, 2024, 2:21pm UTC](https://discuss.elastic.co/t/setting-up-integrations-fortinet/359251/8 "2024-05-14T14:21:29Z")

</div>

> [@riahc3](#):
>
> The how to and documentation isnt clear but if I can use only one agent on the same server

What is not clear? You can only run one agent per server, this is mentioned in multiple places.

So, 1 agent per serer, multiple integrations per agent.

> [@riahc3](#):
>
> Thats something I also dont get about the agent policy; I feel like it should be able to set a ILM for setting hot, warm and cold phases but I dont see it. It isnt intuitive

The ILM policy for the agent and its integrations is managed by the Fleet Server, **all** integrations will use the same ILM policy, but this can be customized.

> [@riahc3](#):
>
> If I have various Windows servers, why do I need various agents? How does that work?

Well, if you want to collect logs from the server, you need an agent running on the server to get those logs and send to elasticsearch.

The Agent is a log collector, to get the logs it needs to have access to the logs, so you need to have one agent per server.

> [@riahc3](#):
>
> Im going to only capture Windows servers, Linux servers, network devices, and thats it. How many agents do I need?

As mentioned, this depends entirely on your infrastructure. If you want to get logs from a server, you need an agent per server, so if you have 100 servers, you need 100 agents, one in each server.

For network devices is a little different, because you need an agent listening on some port, so the best approach is to spin-up some servers that will receive the logs from your network device, like they were Syslog servers for example.

How many of those servers you need depends on the volume of your logs.

The best way to see how all this work is to do a proof of concept to learn and see what you will need in your specific use case, a common mistake that I constantly see is people trying to build everything already in production without testing and learning how it works.

---

<div class="post-metadata">

**Author:** ![riahc3](https://avatars.discourse-cdn.com/v4/letter/r/d6d6ee/32.png) [@riahc3](https://discuss.elastic.co/u/riahc3)\
**Post date:** [May 14, 2024, 3:12pm UTC](https://discuss.elastic.co/t/setting-up-integrations-fortinet/359251/9 "2024-05-14T15:12:04Z")

</div>

```auto
What is not clear? You can only run one agent per server, this is mentioned in multiple places.

So, 1 agent per serer, multiple integrations per agent.

```

So what I understand from what you are saying is that I install the Elastic Agent THE SAME PLACE where I have my ELK stack installed and done? To collect logs from the server itself???

`The ILM policy for the agent and its integrations is managed by the Fleet Server, **all** integrations will use the same ILM policy, but this can be customized.`

The Fleet Server is required when there are SEVERAL servers with SEVERAL Elastic Agent installations. Else, do I really need a Fleet Server? Which, again, in this case, it would be installed in the same server as the ELK Stack.....

> Well, if you want to collect logs from the server, you need an agent running on the server to get those logs and send to elasticsearch.
> 
> The Agent is a log collector, to get the logs it needs to have access to the logs, so you need to have one agent per server.

Ah, so I need to install Elastic Agent on ALSO the Windows and Linux Servers?

`As mentioned, this depends entirely on your infrastructure.`

Windows Servers  
Linux Servers  
Network devices (firewall, switches, etc.)

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 14, 2024, 3:29pm UTC](https://discuss.elastic.co/t/setting-up-integrations-fortinet/359251/10 "2024-05-14T15:29:21Z")

</div>

> [@riahc3](#):
>
> So what I understand from what you are saying is that I install the Elastic Agent THE SAME PLACE where I have my ELK stack installed and done? To collect logs from the server itself???

For example, if you have 3 servers running Elasticsearch and you want to get the logs from those servers, then you need to install the Elastic Agent in each one of the servers.

The Elastic Agent is a log collector, if you want to get a log from a server, you need to agent running on that server. You have thousands of servers and want to get logs from all of them? Then you need to install the agent on each one of them.

> [@riahc3](#):
>
> The Fleet Server is required when there are SEVERAL servers with SEVERAL Elastic Agent installations. Else, do I really need a Fleet Server? Which, again, in this case, it would be installed in the same server as the ELK Stack.....

The Fleet Server is requires no matter if you have one agent or thousand of agents, the management of the agents is done by the fleet server. In the documentation linked before the are links to other documentations that explain how the agent works, this one [here](https://www.elastic.co/guide/en/fleet/current/fleet-server.html) explains what is a Fleet Server, what it will do and the deployment models.

This is description of a Fleet Server:

> Fleet Server is a component that connects Elastic Agents to Fleet. It supports many Elastic Agent connections and serves as a control plane for updating agent policies, collecting status information, and coordinating actions across Elastic Agents. It also provides a scalable architecture. As the size of your agent deployment grows, you can deploy additional Fleet Servers to manage the increased workload.

Where you will install the fleet server is up to you, I recommend having it on a separate server.

> [@riahc3](#):
>
> Ah, so I need to install Elastic Agent on ALSO the Windows and Linux Servers?

Yes, if you want to get the logs from the server you need an agent installed on the server to be able to get the logs.

---

<div class="post-metadata">

**Author:** ![riahc3](https://avatars.discourse-cdn.com/v4/letter/r/d6d6ee/32.png) [@riahc3](https://discuss.elastic.co/u/riahc3)\
**Post date:** [May 14, 2024, 3:41pm UTC](https://discuss.elastic.co/t/setting-up-integrations-fortinet/359251/11 "2024-05-14T15:41:33Z")

</div>

`For example, if you have 3 servers running Elasticsearch and you want to get the logs from those servers, then you need to install the Elastic Agent in each one of the servers.`

I think thats why Im not explaining correctly, sorry 🙂

I will only have ONE server and that server is going to contain everything: Elasticsearch, Kibana, Logstash.....Everything.....

`The Elastic Agent is a log collector, if you want to get a log from a server, you need to agent running on that server. You have thousands of servers and want to get logs from all of them? Then you need to install the agent on each one of them.`

OK, I got you I think. I need to install Elastic Agent on all of the servers I want to collect logs FROM.

WINDOWSSERVER2022-01  
WINDOWSSERVER2022-02  
WINDOWSSERVER2022-03  
WINDOWSSERVER2022-04  
LINUXSERVER-01  
LINUXSERVER-02

All of these need to have it (Elastic Agent) installed to send logs to ElasticKibanaLogstashServer-01, right? I think I understand now, thank you 🙂

`The Fleet Server is requires no matter if you have one agent or thousand of agents, the management of the agents is done by the fleet server. In the documentation linked before the are links to other documentations that explain how the agent works, this one [here](https://www.elastic.co/guide/en/fleet/current/fleet-server.html) explains what is a Fleet Server, what it will do and the deployment models.`

So it is required?

`Where you will install the fleet server is up to you, I recommend having it on a separate server.`

Thats not possible. Is it possible to have it installed on the same server as Elastic, Kibana and Logstash?

`Yes, if you want to get the logs from the server you need an agent installed on the server to be able to get the logs.`

OK, so my first Elastic Agent will be installed on the Elastic, Kibana, Logstash server itself. Gotcha 🙂

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 14, 2024, 3:59pm UTC](https://discuss.elastic.co/t/setting-up-integrations-fortinet/359251/12 "2024-05-14T15:59:28Z")

</div>

> [@riahc3](#):
>
> I will only have ONE server and that server is going to contain everything: Elasticsearch, Kibana, Logstash.....Everything.....

Yeah, you could have everything on the same server, but this is not recommended for many reasons, but if you want you can, just keep in mind that the performance can be impacted.

Also, if you are going to use Elastic Agent, maybe you do not need Logstash.

> [@riahc3](#):
>
> All of these need to have it (Elastic Agent) installed to send logs to ElasticKibanaLogstashServer-01, right?

Yes, you will need one Agent on each onf of those servers.

> [@riahc3](#):
>
> So it is required?

Deploying Fleet managed agents is the recommended way to deploy agents, and in this deployment model a Fleet Server is required, however it is possible to deploy agents in a standalone mode where you manage everything, this is an _advanced use case_ that assumes that you already has experience with both Elastic Stack and Elastic Agents, I would not recommend anyone starting with the Elastic stack to do this.

The differences are explained in the documentation linked in the previous post.

> [@riahc3](#):
>
> Thats not possible. Is it possible to have it installed on the same server as Elastic, Kibana and Logstash?

Yes, you can have everything in one server, it is not recommended, and the performance may not be good, but you can.

---

<div class="post-metadata">

**Author:** ![riahc3](https://avatars.discourse-cdn.com/v4/letter/r/d6d6ee/32.png) [@riahc3](https://discuss.elastic.co/u/riahc3)\
**Post date:** [May 15, 2024, 10:32am UTC](https://discuss.elastic.co/t/setting-up-integrations-fortinet/359251/13 "2024-05-15T10:32:30Z")

</div>

```auto
Yeah, you could have everything on the same server, but this is not recommended for many reasons, but if you want you can, just keep in mind that the performance can be impacted.

Also, if you are going to use Elastic Agent, maybe you do not need Logstash.

```

Due to the infrastructure, everything is gonna be on the same server.

I have Logstash in case I need additional logs and parse them.

` Yes, you will need one Agent on each onf of those servers.`

OK, perfect. I IMAGINE the agents installed on the Windows computers collect logs and then send them directly to Elasticsearch right?

> Deploying Fleet managed agents is the recommended way to deploy agents, and in this deployment model a Fleet Server is required, however it is possible to deploy agents in a standalone mode where you manage everything, this is an _advanced use case_ that assumes that you already has experience with both Elastic Stack and Elastic Agents, I would not recommend anyone starting with the Elastic stack to do this.
> 
> The differences are explained in the documentation linked in the previous post.

Yes, the Fleet way is the suggested way....that being said, the documentation is very badly worded on what is what, how is how, and why is why.

`Yes, you can have everything in one server, it is not recommended, and the performance may not be good, but you can.`

Yeah, I accept that.

---

<div class="post-metadata">

**Author:** ![riahc3](https://avatars.discourse-cdn.com/v4/letter/r/d6d6ee/32.png) [@riahc3](https://discuss.elastic.co/u/riahc3)\
**Post date:** [May 15, 2024, 10:33am UTC](https://discuss.elastic.co/t/setting-up-integrations-fortinet/359251/14 "2024-05-15T10:33:17Z")

</div>

I installed the Fleet and installed the Agent BUT the integration with Fortinet is not working correctly.

---

<div class="post-metadata">

**Author:** ![riahc3](https://avatars.discourse-cdn.com/v4/letter/r/d6d6ee/32.png) [@riahc3](https://discuss.elastic.co/u/riahc3)\
**Post date:** [May 15, 2024, 10:52am UTC](https://discuss.elastic.co/t/setting-up-integrations-fortinet/359251/15 "2024-05-15T10:52:17Z")

</div>

A traffic capture SEEMS to show the traffic arriving to ELK but it isnt processed in any way, shape or form.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/a/5ae864e8f8b47ca6fd46b5eaa3bdd60fca63e5fd.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/0/604554cf29de7411760eed21bfbd5d1857ff0956.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/1/11bf7b6243878508690c12949045f86accde6096.png)

Do you need any other information?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 15, 2024, 12:24pm UTC](https://discuss.elastic.co/t/setting-up-integrations-fortinet/359251/16 "2024-05-15T12:24:05Z")

</div>

You configuration is wrong, you are using localhost, you should use `0.0.0.0`.

Using localhost means that the input will only listen on `127.0.0.1`, which means that it will only accept requests from the same host.

---

<div class="post-metadata">

**Author:** ![riahc3](https://avatars.discourse-cdn.com/v4/letter/r/d6d6ee/32.png) [@riahc3](https://discuss.elastic.co/u/riahc3)\
**Post date:** [May 16, 2024, 7:30am UTC](https://discuss.elastic.co/t/setting-up-integrations-fortinet/359251/17 "2024-05-16T07:30:47Z")

</div>

I thought that was the interface I was gonna listen to which could be 127.0.0.1, the actual IP or 0.0.0.0 which is all interfaces.

I changed it to 0.0.0.0 but same thing

---

<div class="post-metadata">

**Author:** ![riahc3](https://avatars.discourse-cdn.com/v4/letter/r/d6d6ee/32.png) [@riahc3](https://discuss.elastic.co/u/riahc3)\
**Post date:** [May 17, 2024, 8:29am UTC](https://discuss.elastic.co/t/setting-up-integrations-fortinet/359251/18 "2024-05-17T08:29:46Z")

</div>

Maybe Im missing something obvious, so could someone please state a step by step on how to get a integration working?

Things I have done:

Elastic Agent is installed and working:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/6/e68ff73f71902557c32e319f3249ccaf6c787514.png)

As you saw, logs are incoming from the Forti:

![image](https://us1.discourse-cdn.com/elastic/original/3X/2/a/2a67de6afec4937dcb865a156d713354e0efe2d8.png)

The integration is setup:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/7/f7ec3df617b7645270440c1f8a55054b8737df04.png)

Am I missing anything?

---

<div class="post-metadata">

**Author:** ![riahc3](https://avatars.discourse-cdn.com/v4/letter/r/d6d6ee/32.png) [@riahc3](https://discuss.elastic.co/u/riahc3)\
**Post date:** [May 21, 2024, 11:24am UTC](https://discuss.elastic.co/t/setting-up-integrations-fortinet/359251/19 "2024-05-21T11:24:28Z")

</div>

Any suggestions? Thank you

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 21, 2024, 12:15pm UTC](https://discuss.elastic.co/t/setting-up-integrations-fortinet/359251/20 "2024-05-21T12:15:05Z")

</div>

Check the Elastic Agent logs in the server where the integration is running to see if there is any error.

Also, can you do a tcp dump on the same server on the port you are sending the data and share it as plain text? Use the preformatted text option, the `</>` button, it is not possible to see the wireshark print you share, just got a quick tcp dump and share it.

[Next page](https://discuss.elastic.co/t/setting-up-integrations-fortinet/359251.md?page=2)
