Skip to content

kinneygroup/itsi-fortinet-fortigate

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

2 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Summary

The ITSI Content Pack for Fortinet FortiGate from Kinney Group is specifically designed to monitor system health related to Fortinet FortiGate. It leverages Splunk ITSI to provide in-depth analysis and visualization of logs for Fortinet FortiGate, ensuring critical systems are operating optimally. This content pack is an essential tool for IT professionals looking to enhance the reliability and performance of their Fortinet FortiGate infrastructure.

  • Comprehensive Performance Monitoring: Offers detailed insights into Fortinet FortiGate system health, network traffic, and security events, enabling optimized resource utilization.
  • Critical System Status Tracking: Monitors the real-time operational status of Fortinet FortiGate systems, helping IT professionals swiftly identify and address potential issues.
  • Enhanced Security and Efficiency: Facilitates better decision-making on security measures and system adjustments by analyzing performance trends and detecting anomalies across the infrastructure.

This ITSI Content Pack is open source and available for community collaboration and enhancement on GitHub.

For more information about Kinney Group's Splunk Products, visit our website.

Details

The ITSI Content Pack for Fortinet FortiGate contains service definitions and KPIs ready to import to ITSI. The KPI Thresholds and importance values are set to defaults so that they can be tuned manually for your use case. After configuration, this content pack provides a comprehensive monitoring solution for Fortinet FortiGate systems.

Fortinet FortiGate Log Reference

Kinney Group ITSI Content Pack Blog

For more information about Kinney Group's Splunk Products, visit our website.

Services

Fortinet FortiGate monitoring encompasses several specialized services, each targeting specific aspects of system performance and security:

  1. Fortinet FortiGate System Health
    • Description: Monitors overall health and performance of the Fortinet FortiGate system, encompassing all aspects including traffic, security, and event logs.
  2. Traffic
    • Description: Monitors network traffic passing through the Fortinet FortiGate, capturing all data packets and their statuses.
  3. Forward Traffic
    • Description: Monitors forward network traffic and anomalies, focusing on overall traffic flow and identifying irregularities.
  4. UTM
    • Description: Monitors Unified Threat Management (UTM) activities, essential for security by encompassing various threat detection and prevention mechanisms.
  5. Webfilter
    • Description: Monitors web filtering activities, helping in blocking access to malicious or inappropriate websites.
  6. Virus
    • Description: Monitors virus detection and prevention events, crucial for maintaining system integrity and security.
  7. Spam
    • Description: Monitors spam detection and prevention events, important for filtering out unwanted and potentially harmful emails.
  8. Intrusion
    • Description: Monitors intrusion events, including Anomoly and Intrusion Prevention System (IPS) events.
  9. DLP
    • Description: Monitors Data Loss Prevention (DLP) events.
  10. App Control
    • Description: Monitors application control events, essential for managing and securing application usage within the network.
  11. Event
    • Description: Monitors system and security events, providing detailed information about system operations and security incidents.
  12. VPN
    • Description: Monitors VPN-related events, critical for secure remote access and connectivity.
  13. System
    • Description: Monitors system-related events, providing detailed information about the operational status and changes within the Fortinet FortiGate system.
  14. Wireless
    • Description: Monitors wireless network events, essential for managing and securing wireless network access.
  15. User Authentication
    • Description: Monitors user authentication successes and failures.

And more!

Relationships

Dependencies:

Services are interconnected.

Hierarchical Structure:

Some services form a hierarchy, illustrating a layered approach to performance monitoring where base metrics support broader performance indicators.

Installation

Installation prerequisites:

Fortinet FortiGate Add-On for Splunk

Splunk App for Content Packs

Splunk ITSI

Troubleshooting

Kinney Group ITSI Content Pack Blog

Github and Readme

support@kinneygroup.com

Contact

To provide feedback, visit our Github and Readme for our content packs.

support@kinneygroup.com

For more information about Kinney Group's Splunk Products, visit our website.

Version History

Version Date Description
0.0.1 06/03/24 Initial Preview Release

Considerations:

Kinney Group ITSI Content Pack Blog

Releases

No releases published

Packages

No packages published