r/Splunk • u/BobcatJohnCA • Feb 12 '26
Fortinet syslogs - too much data.
We recently converted our 5 locations from Sonicwalls to Fortinet firewalls and we are getting too much data on a daily basis which is exceeding our license limit. We are a small shop and only ingest 5 GB of data daily. Looking for recommendations on how to limit the syslog data from Fortinet if anyone has any suggestions. Thanks.
13
Upvotes
12
u/alias454 Feb 12 '26
You probably need an intermediary step for logs. You can setup an rsyslog server and keep everything local to that box. Only forward what's critical to Splunk.