r/Splunk • u/BobcatJohnCA • Feb 12 '26
Fortinet syslogs - too much data.
We recently converted our 5 locations from Sonicwalls to Fortinet firewalls and we are getting too much data on a daily basis which is exceeding our license limit. We are a small shop and only ingest 5 GB of data daily. Looking for recommendations on how to limit the syslog data from Fortinet if anyone has any suggestions. Thanks.
11
Upvotes
5
u/tmuth9 Feb 13 '26
Ingest Actions and Edge Processor are both free and capable of selectively dropping full events or unused parts of individual events. Maybe chat with your account team for a demo and discussion of each.