Question
Disappointed ... reporting etc.
Hi all, I' m finding my new shiny Fortianalyser rather impenetrable. The default reports are worse than useless and I find myself really rather disappointed compared to a standard old syslog server! I wonder whether some of the knowledgeable people here could answer a few questions? - is it possible to just run SQL queries directly and receive the output ? (or does it have to be integrated into a chart/report etc.) - is there a guide to using SQL on the Fortianalyzer somewhere? - is there a schema somewhere to know what columns I might even use? Sort of questions I want to answer are... - which user accessed a specific/host/ip address and when - what traffic is being exchanged between specific ip addresses etc. etc. I' m sure there will be more :-) Thanks, Jon