FortiGate with SSL VPN.
The historic logs for users connected through SSL VPN can be viewed under a different location depending on the FortiGate version:
It is necessary to use the Add Filter option to add 'Action: tunnel-Up' or 'Action: tunnel-down' depending on requirements as shown in the following screenshots.
Once the log has been selected for the required date, the user identifier will be shown as part of the detailed log display. In the following examples, user 'mb' is connected through SSL VPN.
It should be noted that the filter name 'User' is only available from FortiOS v5.4.1 and above. For previous versions select Filter 'Action'.
Make sure that the VPN activity event is enabled.
To log VPN events from the GUI: