Skip to main content
mac987
New Member
November 25, 2020
Question

Using LDAP Query for Report filters

  • November 25, 2020
  • 0 replies
  • 1609 views

Hi

 

We are running FG and FA, V 6.2.3

 

I cant find an answer to this anywhere within the FA forum, can you help.

 

We have different remote FG FW's dotted around the country feeding logs into FA with user groups routing through certain firewalls.

 

I have created different reports to query the separate firewalls for suspicious keyword activity per user but when I view the report every user is in every different report not the specific users who route through the specific firewall.

 

I have then tried with filters to the LDAP server setup within the FG copying the exact details pf our LDAP server setup within the GUI to the LDAP server report configuration within the LDAP Queiry filter section but when i run the report nothing changes, i still see all the traffic from every user not just specific users within that LDAP group.

 

In the filters section i have selected group then in the value field i have entered the group exactly as its setup within the FG GUI, an example group name being( with spaces in it )  PDB JB - WPB 1, i have also entered this into the value field within double quotes but nothing changes. I have also entered the long LDAP group starting OU but still the same data for every user.

 

Has anybody got LDAP report filtering working if so can you help please ?

 

Thanks in advance for everyone's help

 

Mac

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!