| Description | This article describes how to troubleshoot a FortiAnalyzer custom report filter when it is not working becausee missing 'filter' info in the dataset. |
| Scope | FortiAnalyzer. |
| Solution |
Below is the scenario: At FortiAnalyzer (Device Manager), 2 FortiGates have been added.
For example:
At FortiAnalyer, the '10.100.5.172' IP address is only inside FGT_HQ logs.
At FortiAnalyzer, the Dataset information is as below.
At FortiAnalyzer, generate the report, the result shows more information that is not included in the filter FortiGate. Below is the comparison between 2 different datasets and 2 different results.
Correct the dataset as below:
SELECT from_dtime(dtime) as time, devname, policyid, srcip, dstip, hostname, catdesc, utmaction FROM $log WHERE $filter AND utmaction = 'block' ORDER BY dtime DESC |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.