FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
Dante_De_Luca_FTNT
Article Id 198304
Description
This article explains how to run a report on traffic from a specific subnet.

Scope
FortiAnalyzer v5.2, v5.4

Solution
This can be done through the filter settings on the report.

FortiAnalyzer v5.2
Go to Reports > edit the report in question > Advanced Settings > Filters

FortiAnalyzer v5.4

Go to Reports > edit the report in question > Settings > Filters

The FortiAnalyzer supports filtering by subnet using the following filter syntax:
    srcip equal to 192.168.100.*
    srcip equal to 192.168.100.0/24.
It should be noted that subnet filtering cannot be done from within the database.

Contributors