FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
akaratas
Staff
Staff
Article Id 351861
Description

 

This article describes how to check admin login attempts on FortiAnalyzer for all FortiGate using LogView, FortiView and Report.

 

Scope

 

FortiAnalyzer, FortiAnalyzer Cloud.

 

Solution

 

The first option is to use Log View to check successful or unsuccessful Admin login attempts to all FortiGates: Go to LogView -> FortiGate -> Event -> System, select All Devices as a filter like the below screenshot:

 

1.png

 

Define the time range like below screenshot as logs need to be checked:

 

2.png

 

  • The second option is to use FortiView to check successful or unsuccessful Admin login attempts to all FortiGates under FortiView -> System -> Admin Logins, select All Devices as a filter like the below screenshot:

 

3.png

 

Define the time range like below screenshot as logs need to be checked:

 

4.png

 

Add Filter Action = Login:

 

1.png

 

  • The third option is to create a Report to check successful or unsuccessful Admin login attempts to all FortiGates under Report -> All Reports and use the Security Analysis Report.

 

5.png

 

Define the time range like the one in the following screenshot as a report needs to be created.

 

6.png

 

Security Analysis Report outputs can be seen below.

 

7.png