Skip to main content
vraev
Staff
Staff
January 13, 2025

Technical Tip: Hostname/FQDN search in FortiAnalyzer logs

  • January 13, 2025
  • 0 replies
  • 3433 views
Description

 

This article explains how to search for and preview the hostname or FQDN in LogView.

 

Scope

 

FortiAnalyzer.

 

Solution

 

When reviewing the hostname/FQDN, the FortiGate or FortiAnalyzer should resolve them. To enable the proper settings, see the following article: Technical Tip: Configuring FortiGate and FortiAnalyzer to resolve IPs to hostname

 

After these steps: under the LogView -> FortiGate -> Traffic, the column 'Destination Name' (dstname) should be enabled under 'More Columns' to display the resolved PTR records.

 

FAZ_FQDN.png

 

Then, use the search bar and a filter for 'destination name'.

 

FAZ_FQDN_search.png

 

Related articles:

Technical Tip: API calls to search logs from analytics DB / LogView / in FortiAnalyzer

Technical Tip: Configuring FortiGate and FortiAnalyzer to resolve IPs to hostname

Technical Tip: Hostname and Destination name in traffic and UTM logs in FortiOS