EMS-Server logview FCT WF Events on EMS-Server GUI
Hi @ all,
we have a Customer running FortiClients on their Endpoints and using an EMS-Server (v7.2.4 build 0983),
in the GUI section, Administration > Log Viewer, i can only see EMS-Server generated Events,
LDAP queries, admin logon Events, Settings updated etc., but no "on Endpoint x generated FCT Logs", like Security Events, FCT Web Filter block events as example.
Correct me please if i wanna see this events "FCT WebFilter" i have to go GUI: Endpoints > all Endpoints > search for Endpoint which got issues > execute >Action request FortiClient Logs, then search in the fclog.dat for the related log?
I was wondering because in the GUI Section Quarantine Managment > Files, in this Tab are Files and Endpoint listed, so the FortiClient forward this information via FortiTelemetry to the EMS-Server, triggered by scheduled AV-Scan or may on-prem Scan.
So is there the possibility to see this FCT-WF "Block" Events without the need of this Steps:
GUI: Endpoints > all Endpoints > search for Endpoint which got issues > execute >Action request FortiClient Logs
Thanks
me and my other selves <3 Fortinet
