You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Fortinet日志已被Filebeat接收,但Kibana安全应用无数据显示求助

Kibana Security App看不到FortiGate日志?试试这些排查步骤

先确认数据有没有真的进Elasticsearch

  • 执行命令检查Filebeat到ES的连通性:
    filebeat test output
    
    输出需显示"OK",否则先解决链路连通问题。
  • 查询ES中是否存在FortiGate相关索引:
    curl -X GET "http://localhost:9200/_cat/indices?v"
    
    需看到名称包含filebeat-*-fortinet-firewall-*的索引,且文档数大于0,说明数据已成功传入ES。

检查Security App的索引模式配置

Kibana Security App仅识别特定索引模式,需确认配置正确:

  1. 登录Kibana,进入「Stack Management」→「Index Patterns」
  2. 查看是否存在匹配FortiGate日志的索引模式(如filebeat-*),若没有则手动创建:
    • 输入索引模式filebeat-*-fortinet-firewall-*,点击「Next step」
    • 选择@timestamp作为时间字段,完成创建
  3. 进入「Security」→「Settings」→「Indices」,将刚创建的索引模式添加到Security App的索引列表中。

验证日志字段是否符合Security App要求

Security App需要特定字段才能展示数据,可查询单条日志确认:

curl -X GET "http://localhost:9200/filebeat-*-fortinet-firewall-*/_search?size=1"

重点检查是否包含以下关键字段:

  • event.category: "network"
  • event.type为connection、allowed或denied等类型
  • source.ip、destination.ip、source.port、destination.port等网络字段

若字段缺失,大概率是Filebeat模块解析异常:

  • 确认Fortinet模块已启用:
    filebeat modules list
    
    需看到fortinet旁标注enabled。
  • 重新加载模块配置并重启Filebeat:
    filebeat setup --modules fortinet
    systemctl restart filebeat
    

调整FortiGate的syslog格式

默认syslog格式可能存在解析问题,尝试修改格式:

  1. 登录FortiGate,修改syslogd配置:
    config log syslogd setting
      set format csv
      set facility local0
      set status enable
      set server "192.168.37.2"
      set port 9004
    end
    
    CSV格式更易被Filebeat解析,也可尝试default格式。
  2. 手动触发流量(如通过FortiGate后的设备访问外网)生成新日志,再检查ES中的解析情况。

检查时间范围选择

有时是时间范围设置错误导致无法看到数据:

  • 进入Security App后,点击右上角时间选择器,选择覆盖日志生成时间段的范围(如「最近15分钟」)。

内容的提问来源于stack exchange,提问作者morad della3

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.24 14:06:18