Skip to main content
preussenotto
New Member
December 8, 2025
Question

Fortigate & Fortianalyzer

  • December 8, 2025
  • 1 reply
  • 193 views

I need a way to tie user activity with the fortigate firewall logs.  I have source IP information but I need a way to also collect which AD user is doing that.  I have looked at some of the utilities on the download page but those look like SSO type things.  I dont need users to sign-in or authenticate, but I do need the log files to show per-user activity.  We are using 70F's on 7.6.4 firmware.

Palo Alto Networks products allow this with either a USER-ID agent or CID setup.  I need the fortinet equivalent.

1 reply

kaman
Staff
Staff
December 9, 2025

Hi preussenotto,

Usernames can be included in logs, instead of just IP addresses.

Please refer to the document below for the detailed information:

https://docs.fortinet.com/document/fortigate/7.6.4/administration-guide/802972/include-usernames-in-logs


If you have found a solution, please like and accept it to make it easily accessible to others.


Regards,
Aman

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.