Can't see messages from Fortigate


(Łukasz Michałek) #1

Hello,

I have new graylog 2.2.1 installation on ubuntu server 16.04. It works fine with all of our network devices but when I enabled logging from our fortigate cluster I can’t see those logs. Graylog is processing messages from fortigate I see significantly grow of In and Out messages so messages are processed, but I can’t see those logs in sources or cat’t search it. Where could be the problem?

Best regards,
Lukasz


(Jochen) #2

Try using a Raw/Plaintext input and extract the fields relevant for you with extractors or processing pipeline rules.

http://docs.graylog.org/en/2.2/pages/extractors.html
http://docs.graylog.org/en/2.2/pages/pipelines.html


(Łukasz Michałek) #3

Plaintext helped. Now I need to build some extractors. Thanks for help!


(system) #4

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.