All Apps and Add-ons

Splunk for Fortinet FortiOS 5: How oto get the Traffic Dashboard to resolve a hostname for the destination IP address?

Monkey101
New Member

I am struggling to get the Traffic Dashboard to resolve a hostname for the destination IP address.
Is anyone able to assist with a solution for this?

0 Karma

open3s
Explorer

Hi,
We've just added a new version of the app. Please check if this solves your issues.
Thanks,
Open3S.

0 Karma

splunker12er
Motivator

No, its not solved yet

0 Karma

satishsdange
Builder

Could you please share sample logs & search, you are using.

0 Karma

splunker12er
Motivator
search source_ip="*" destination_ip="*" destination_port="*" user="*" device_name="*" application="*" sourcetype="fortios5_traffic" | fillnull device_name vdom source_interface source_ip user group destination_interface destination_ip session_type destination_port application service action policy_id bytes_sent bytes_received destination_country | stats count by device_name vdom source_interface source_ip user group destination_interface destination_ip session_type destination_port application service action policy_id bytes_sent bytes_received destination_country _time

where source_ip,destination_ip,destination_port fields are not yet extracted by the sourcetype "fortios5_traffic" ?

0 Karma
Get Updates on the Splunk Community!

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...