Description | This article describes setting up FortiAnalyzer custom report to analysis FortiGate rules. |
Scope | FortiAnalyzer 7.x and earlier. |
Solution |
In enterprise environments, network security teams often require detailed visibility into firewall traffic to identify trends, optimize rule sets, and ensure compliance with security policies. FortiAnalyzer provides a powerful reporting engine that allows the creation of custom datasets and reports, making it possible to extract precise insights from FortiGate logs. This article demonstrates how to build a custom report in FortiAnalyzer focusing on firewall policy utilization, using two datasets that highlight traffic distribution by destination ports and by applications.
Dataset 1: Policy Traffic by Destination Port.
The first dataset provides a breakdown of sessions and traffic volume (bytes) per firewall policy, aggregated by the destination port. This allows analysts to identify which services (e.g., HTTPS, DNS, or custom ports) are most utilized within a specific policy.
Use Case:
Dataset 2: Policy Traffic by Application and Category:
The second dataset provides a more granular view of traffic, analyzing policies by application category and specific application. In addition to session counts, it also aggregates the total traffic in bytes, providing both volume and frequency insights.
Use Case:
Creating Chart Libraries:
After defining the datasets, the next phase is to design visual components that will bring the data to life inside the custom report. FortiAnalyzer uses Chart Libraries, which allow building reusable visualizations that can be easily inserted into multiple reports.
Chart Library 1: Policy Traffic by Destination Port.
For the dataset that aggregates traffic by destination port, the most effective visualization is a table.
This visualization provides an immediate overview of which firewall rules are responsible for the largest share of traffic and highlights the most frequently used services.
Chart Library 2: Policy Traffic by Application and Category.
For the dataset that aggregates traffic by destination port, the most effective visualization is a table.
This chart provides a clear picture of the distribution of traffic across categories such as Business, Social Media, Cloud, or Unknown. It helps organizations evaluate whether bandwidth is being consumed by business-critical or non-essential applications.
Building the Final Report. With both datasets and their corresponding chart libraries created, the final step is to design a clean and structured report inside FortiAnalyzer. Reports allow combining visualizations, tables, and text descriptions into a professional document that can be scheduled or shared with stakeholders.
Report Creation Steps:
Follow an example.
DataSet Policy by application:
DataSet Policy by Destination port:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.