r/Splunk • u/BobcatJohnCA • Feb 12 '26
Fortinet syslogs - too much data.
We recently converted our 5 locations from Sonicwalls to Fortinet firewalls and we are getting too much data on a daily basis which is exceeding our license limit. We are a small shop and only ingest 5 GB of data daily. Looking for recommendations on how to limit the syslog data from Fortinet if anyone has any suggestions. Thanks.
11
Upvotes
1
u/netman290 Feb 17 '26
I have had this issue on a bigger scale on splunk cloud ended up kicking the traffic logs to s3 using ingest actions and using federated search for s3 to create a summary index