Fortinet black logo

User Guide

24.2.0

Estimator mode

Estimator mode

The NetFlow estimator allows you to get your estimated NetFlow volume.

This step is optional.

  1. Run the installer in Estimator mode by running the following command:
    bash install-fortimonitor-netflow.sh -re y
    This installs the NetFlow estimator and will not register the appliance to FortiMonitor. See Installation parameters for more details.

  2. Upload the log files which includes your usage data. This will be used to get your estimated NetFlow volume.
    fortimonitor-netflow upload-logs <customer_key>

Switch to Collector mode

If you used the Estimator mode, switch to Collector mode to begin collecting and monitoring flow data. To do this, perform the following steps:

  1. Stop NetFlow monitoring by running the following command:
    fortimonitor-netflow stop

  2. Register your NetFlow collector appliance with FortiMonitor by running the following command:
    fortimonitor-netflow register -c <customer_key> -a <appliance_name>
    Where:

    • <customer-key> is your own customer key. To obtain your customer key, visit the FortiMonitor control panel and click your account name then select My FortiMonitor Account.

    • <appliance_name> is the name of the appliance to be registered. This name will be used to help identify the flows in the NetFlow dashboard in the FortiMonitor control panel.

  3. To begin collection, run the following command:
    fortimonitor-netflow start

Estimator mode

The NetFlow estimator allows you to get your estimated NetFlow volume.

This step is optional.

  1. Run the installer in Estimator mode by running the following command:
    bash install-fortimonitor-netflow.sh -re y
    This installs the NetFlow estimator and will not register the appliance to FortiMonitor. See Installation parameters for more details.

  2. Upload the log files which includes your usage data. This will be used to get your estimated NetFlow volume.
    fortimonitor-netflow upload-logs <customer_key>

Switch to Collector mode

If you used the Estimator mode, switch to Collector mode to begin collecting and monitoring flow data. To do this, perform the following steps:

  1. Stop NetFlow monitoring by running the following command:
    fortimonitor-netflow stop

  2. Register your NetFlow collector appliance with FortiMonitor by running the following command:
    fortimonitor-netflow register -c <customer_key> -a <appliance_name>
    Where:

    • <customer-key> is your own customer key. To obtain your customer key, visit the FortiMonitor control panel and click your account name then select My FortiMonitor Account.

    • <appliance_name> is the name of the appliance to be registered. This name will be used to help identify the flows in the NetFlow dashboard in the FortiMonitor control panel.

  3. To begin collection, run the following command:
    fortimonitor-netflow start