Vendor Sheet
Fortinet FortiGate App for Splunk: Simplified Threat Investigation and Analytics
The Fortinet FortiGate App for Splunk aggregates, visualizes, and analyzes large volumes of logs from physical and virtual FortiGate firewalls. Built-in Threat and UTM dashboards help analysts identify anomalies, remove duplicate events, examine attack severity, correlate source and destination activity, and monitor applications, users, IPS events, malware, web filtering, authentication, VPNs, and configuration changes. Real-time and historical views support faster detection, response, recovery, compliance analysis, and data center or cloud monitoring. The companion FortiGate Add-On maps FortiGate information into Splunk Enterprise Security data models, including access, endpoint malware, network traffic, and security events. Support for virtual domains, NAT, transparent mode, and common p
