Skip to main content

Fortinet Network Copilot correlates FortiGate logs with Splunk

Companies mentioned

The vendor describes a live deployment of Network Copilot (NCP) that ingests FortiGate telemetry, correlates it with Splunk-indexed logs, and answers operational questions in natural language to support faster troubleshooting for L1 and L2 teams.

Research Overview

The post positions NCP as an agentic platform for NetOps operations, intended to connect fragmented telemetry sources across network security and operational systems.

It describes an implementation that installs an intelligent agent on FortiGate firewalls to forward Metrics, Events, Logs, and Traces to Splunk for collection and indexing.

Key Findings

The article states that NCP can correlate and query Splunk data to produce contextual responses to operator questions.

It also describes the ability to store telemetry directly on the platform for real-time analysis of historical telemetry alongside answers drawn from Splunk.

Technical Breakdown

According to the description, NCP parses configuration and log data from multiple device categories, including SIEM sources, routers, switches, and firewalls, to support real-time analysis for root-cause and related troubleshooting workflows.

The post outlines functional capabilities such as log ingestion and normalization, cross-domain correlation, natural-language interaction, explainable root-cause analysis, and guided remediation without risky automated fixes.

Operational Impact

The deployment is described as running with live FortiGate traffic inline with production-like conditions, exporting traffic, authentication, threat, system, configuration, and audit logs to Splunk.

Through the shown examples, the article describes day-to-day use cases including identifying configuration changes within a 24-hour window, explaining failed login attempts based on user and source IP, and diagnosing denied traffic due to implicit policy when a user cannot access the internet.

Conclusion

The post frames NCP as an agentic approach to correlate FortiGate and Splunk telemetry and provide explainable, context-aware answers to operational questions for L1 and L2 troubleshooting. This “Blog Signals brief” is a fact-based summary of the vendor blog.

Blog post, originally published by Khurram Khani, Amrit Singh Sardar at aviznetworks.com.

Graph Connections

3 companies named across 2 categories, one of 62 sources referencing Fortinet. Previous coverage: Aviz Networks details Network Copilot for network operations (August).