Recently I have installed this content pack (https://github.com/pfitchie/graylog3.Fortigate6xContentPack) on my Graylog Server to capture the Fortigate logs. I use a Graylog OVA which version is 3.3.3. So my problem is this: the messages are arriving to my Graylog server but i cannot visualize it. Of course i am redirecting the messages from port 514 to 1025 with an Iptables rule.
And what is your problem? You don’t see parsed fields or dashboard?
Content pack contains extractors, so check if there are in Manage exctractor button in Input FortiGate
Content pack contains parameters for input and stream. Did you setup correct fghostname parameter so it contains your real fortigage hostname e.g. FG123456789?
I do not recomment forward logs from 514, it’s better to use higher number than 1024 for input and directly send to this port from fortigate.
Content pack contains dashboard, but it will not probably work, because content pack was created for 3.1 version, and 3.2/3.3 hase different dashboard functionality.
OK! i check and configure all you say me but i cannot see anything on the section Show received messages However now i can see some statistics on Dashboard section
Maybe you have problem with timestamps, try to select all messages in timeframe selector, or use absolute time selector and check also future messages.
It’s normal problem, if first message which contains level setup as numeric (which uses elestic search for ), and another message want to insert another type (string) to elastic.
My problem has been resolve! i have removed the input created by the content pack and then i have created my own. All this after sync the timestamps. Thank you so much.