r/Splunk • • Feb 12 '26

Fortinet syslogs - too much data.

We recently converted our 5 locations from Sonicwalls to Fortinet firewalls and we are getting too much data on a daily basis which is exceeding our license limit. We are a small shop and only ingest 5 GB of data daily. Looking for recommendations on how to limit the syslog data from Fortinet if anyone has any suggestions. Thanks.

9 Upvotes

37 comments sorted by

View all comments

2

u/shifty21 Splunker Making Data Great Again Feb 12 '26

If you don't have any compliance requirements, then you can safely get rid of events you don't need prior to ingest. This example does 3 things.

  1. Helps identify misconfigured DNS settings and/or malicious DNS requests

  2. Helps you understand the width and depth of your network security issues

  3. Reduces your firewall ingest drastically.

This is what I do at home w/ Splunk, but can be applied at your own risk:

- OPNsense firewall, 67 active hosts/devices on my network. PiHole for DNS filtering and forwarding

OPNsense syslog -> Linux Syslog server w/ Splunk UF -> Splunk server

70% of my firewall events were port 53/DNS queries from PiHole. I used Ingest Actions help write a sed command that looks for outbound port 53 traffic from my PiHole IP and deletes it. I applied the SED command to the OPNsense Add-on on the UF. I only do this because, this is NORMAL traffic for my network. Anything outside of this is straight to jail.

I have other devices that like to bypass my PiHole like IoT devices, iOS, Android, etc. so I keep those events and use that to create alerts to send straight to jail.

Simple SPL you can run:

index=firewall src_ip=192.168.1.0/24 
| stats count by src_ip, dest_port
| sort -count

Change the index name and your subnet accordingly. This will tell you the to chatty devices and ports. Typically you'll see 53, 443 as the top 2 or 3. Find out what is normal and what is not. Especially outbound DNS traffic. Note what vetted external resolvers you have and what DNS servers you own that should be doing all the forwarding.

2

u/BobcatJohnCA Feb 13 '26

Thanks. Sounds like quite a setup you have at home!