I want to customize the FortiAnalyzer report
We are planning to implement Dynamic IP pools for IoT users, where the same IP address may be assigned to different users at different times. In the FortiAnalyzer report for Top Applications Bandwidth by user drilldown, we want the report to generate double entries with timestamps for an IP address if it is assigned to both User 1 and User 2, and they use the same applications. To achieve this requirement, we need to modify the FortiAnalyzer report dataset's SQL query. Can anybody provide any inputs on this?
Note: The dynamic IP pools will be implemented on another firewall that is not directly connected to the FortiAnalyzer. However, our firewall is directly connected to FortiAnalyzer, and it receives IoT device traffic through an IPsec tunnel with users Source IP.
