FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
vraev
Staff
Staff
Article Id 369802
Description

 

This article describes how to search and preview the hostname/FQDN in the LogView.

 

Scope

 

FortiAnalyzer.

 

Solution

 

When reviewing the hostname/FQDN, the FortiGate or FortiAnalyzer should resolve them.

To enable the proper settings, see the following article:

Technical Tip: Configuring FortiGate and FortiAnalyzer to resolve IPs to hostname

 

After these steps: under the LogView -> FortiGate -> Traffic, the column 'Destination Name' (dstname) should be enabled under 'More Columns' to display the resolved PTR records.

 

FAZ_FQDN.png

 

Then, use the search bar and a filter for 'destination name'.

 

FAZ_FQDN_search.png

 

Related article:

Technical Tip: API calls to search logs from analytics DB / LogView / in FortiAnalyzer