Fortinet Network Copilot correlates FortiGate logs with Splunk
Companies mentioned
The vendor describes a live deployment of Network Copilot (NCP) that ingests FortiGate telemetry, correlates it with Splunk-indexed logs, and answers operational questions in natural language to support faster troubleshooting for L1 and L2 teams.
Research Overview
The post positions NCP as an agentic platform for NetOps operations, intended to connect fragmented telemetry sources across network security and operational systems.
It describes an implementation that installs an intelligent agent on FortiGate firewalls to forward Metrics, Events, Logs, and Traces to Splunk for collection and indexing.
Key Findings
The article states that NCP can correlate and query Splunk data to produce contextual responses to operator questions.
It also describes the ability to store telemetry directly on the platform for real-time analysis of historical telemetry alongside answers drawn from Splunk.
Technical Breakdown
According to the description, NCP parses configuration and log data from multiple device categories, including SIEM sources, routers, switches, and firewalls, to support real-time analysis for root-cause and related troubleshooting workflows.
The post outlines functional capabilities such as log ingestion and normalization, cross-domain correlation, natural-language interaction, explainable root-cause analysis, and guided remediation without risky automated fixes.
Operational Impact
The deployment is described as running with live FortiGate traffic inline with production-like conditions, exporting traffic, authentication, threat, system, configuration, and audit logs to Splunk.
Through the shown examples, the article describes day-to-day use cases including identifying configuration changes within a 24-hour window, explaining failed login attempts based on user and source IP, and diagnosing denied traffic due to implicit policy when a user cannot access the internet.
Conclusion
The post frames NCP as an agentic approach to correlate FortiGate and Splunk telemetry and provide explainable, context-aware answers to operational questions for L1 and L2 troubleshooting. This “Blog Signals brief” is a fact-based summary of the vendor blog.
Blog post, originally published by Khurram Khani, Amrit Singh Sardar at aviznetworks.com.