FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
akaratas
Staff
Staff
Article Id 351981
Description

 

This article describes checking FortiAnalyzer logs to identify configuration changes on FortiGate.  

 

Scope

 

FortiAnalyzer, FortiAnalyzer Cloud.

 

Solution

 

On FortiAnalyzer, it is possible to filter the logs to identify what objects/settings were configured or changed on FortiGate(s).

 

  • Go to Log View -> FortiGate -> System.
  • Filter for a specific FortiGate or all FortiGates.

1.png

 

  • Define a time range to check logs.

2.png

 

  • Add Filter -> Log Description = Object Attribute Configured or Attribute Configured.

3.png

4.png

 

Related articles:

How to check/filter configuration changes logs