FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
jasonhong
Staff & Editor
Staff & Editor
Article Id 191786
Description
This article describes how to generate a report with log field as a filter.
For this demonstration, report will be created based on filter of User = test user.

Solution
1) Check that there are traffic logs with 'User' field.





2) Apply report filter under 'Report Settings'.
Log Field:User, Match criteria:Equal To, Value:test user    <-----Check the below screenshot.
This will only populate report data for 'test user'.




3) Report output data will only show for 'test user' as per below screenshot from sample report.



Contributors