FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
WinterSnowYap
Article Id 421377
Description This article describes how to troubleshoot a FortiAnalyzer custom report filter when it is not working becausee missing 'filter' info in the dataset.
Scope FortiAnalyzer.
Solution

Below is the scenario:

At FortiAnalyzer (Device Manager), 2 FortiGates have been added.

 

For example:  

  • FGT_HQ
  • FGT_Branch

 

202512_FAZ custom report filter_001.jpg

 

At FortiAnalyer, the '10.100.5.172' IP address is only inside FGT_HQ logs.

 

202512_FAZ custom report filter_002.jpg

 

At FortiAnalyzer, the Dataset information is as below.

 

202512_FAZ custom report filter_003.jpg

 

At FortiAnalyzer, generate the report, the result shows more information that is not included in the filter FortiGate.

Below is the comparison between 2 different datasets and 2 different results.

 

202512_FAZ custom report filter_004a.jpg

 

202512_FAZ custom report filter_004b.jpg

 

 

Correct the dataset as below:

 

SELECT

          from_dtime(dtime) as time,

    devname,

    policyid,

    srcip,

    dstip,

    hostname,

    catdesc,

          utmaction

FROM

          $log

WHERE

          $filter AND utmaction = 'block'

ORDER BY

          dtime DESC