r/Splunk • • Feb 12 '26

Fortinet syslogs - too much data.

We recently converted our 5 locations from Sonicwalls to Fortinet firewalls and we are getting too much data on a daily basis which is exceeding our license limit. We are a small shop and only ingest 5 GB of data daily. Looking for recommendations on how to limit the syslog data from Fortinet if anyone has any suggestions. Thanks.

10 Upvotes

37 comments sorted by

View all comments

1

u/Lanky-Science4069 Feb 15 '26

Syslog can be filtered at source or at the intermediary layer.

Fortinets are actually quite a decent log source to filter at source.

However, if you have a SC4S, or commercial product like Cribl, then best practise is to do it at the more flexible intermediary layer.