Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Analytics using two different log sources
Hello,
I am trying to create a report which would require data from two different log sources or events.
One event is the initial login of the VPN user, which has their username, login success/failure and their Source IP (which is their actual public IP allocated by the ISP).
The other logs contain their general traffic logs, and the important info in these logs is the tunnel IP they have been allocated once they have connected to the corporate VPN.
I can do the reports and dashboards for both these events individually.
Is there anyone to combine these two logs or events and extract the important info from both and present it as one output/report.
Regards,
Ali.
I am trying to create a report which would require data from two different log sources or events.
One event is the initial login of the VPN user, which has their username, login success/failure and their Source IP (which is their actual public IP allocated by the ISP).
The other logs contain their general traffic logs, and the important info in these logs is the tunnel IP they have been allocated once they have connected to the corporate VPN.
I can do the reports and dashboards for both these events individually.
Is there anyone to combine these two logs or events and extract the important info from both and present it as one output/report.
Regards,
Ali.
Solved! Go to Solution.
Labels:
- Labels:
-
SIEM
1 Solution
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Ali,
To build on Karn suggestion, you can also use a Nested search. Check here https://help.fortinet.com/fsiem/6-1-0/Online-Help/HTML5_Help/Nested_queries.htm
If you are able to share the events from both your searches, I can have a go at building the nested search for you.
Cheers
Dan
------------------------------
Daniel
FortiSIEM Product Manager
------------------------------
To build on Karn suggestion, you can also use a Nested search. Check here https://help.fortinet.com/fsiem/6-1-0/Online-Help/HTML5_Help/Nested_queries.htm
If you are able to share the events from both your searches, I can have a go at building the nested search for you.
Cheers
Dan
------------------------------
Daniel
FortiSIEM Product Manager
------------------------------
2 REPLIES 2
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Ali,
It's not perfect, but you can take your two existing report criteria and put them into one query using OR. (1st Report Parameters) OR (2nd Report Parameters). Then use the displayed columns to display the fields you would like.
It's not perfect, but you can take your two existing report criteria and put them into one query using OR. (1st Report Parameters) OR (2nd Report Parameters). Then use the displayed columns to display the fields you would like.
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Ali,
To build on Karn suggestion, you can also use a Nested search. Check here https://help.fortinet.com/fsiem/6-1-0/Online-Help/HTML5_Help/Nested_queries.htm
If you are able to share the events from both your searches, I can have a go at building the nested search for you.
Cheers
Dan
------------------------------
Daniel
FortiSIEM Product Manager
------------------------------
To build on Karn suggestion, you can also use a Nested search. Check here https://help.fortinet.com/fsiem/6-1-0/Online-Help/HTML5_Help/Nested_queries.htm
If you are able to share the events from both your searches, I can have a go at building the nested search for you.
Cheers
Dan
------------------------------
Daniel
FortiSIEM Product Manager
------------------------------
