FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
Dante_De_Luca_FTNT
Article Id 198304

Description

 
This article explains how to run a report on traffic from a specific subnet.


Scope

 
FortiAnalyzer v5.4 v5.6 v6.0 v6.4 v7.0 v7.2.


Solution

 
This can be done through the filter settings on the report.

FortiAnalyzer v5.4+.
 
Go to Reports -> Edit the related report -> Settings -> Filters.

The FortiAnalyzer supports filtering by subnet using the following filter syntax:
 
srcip equal to 192.168.100.*
srcip equal to 192.168.100.0/24
srcip equal to 192.168.1.60-192.168.1.70, 10.200.13.0/24, 192.168.1.177
 
It should be noted that subnet filtering cannot be done from within the database.