Repeated count



Anyone know how repeated log in FortiAnalyzer works?


For example, if I query a Youtube bandwidth usage using "where" filter as "hostname like ''"

It will return serveral results with different Application signatures. For example:



Like you can see, we have the same hostname for two different App's signature. These are different traffic and should be sum or are repeated traffic and I need just one? 


I have the same doubts for others cases, for example:

If an user using Google Chrome access Facebook website, on Log we will see signatures match to HTTP.BROWSER_Chrome AND Facebook. I can sum both sessions/bandwidth usage?




Paulo Raponi

