- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Daily Analyzer report
I am using FortiAnalyzer 5.4.
for daily bandwidth report, eg Top Application Users by Bandwidth, why is it that under User (or IP) column it always shows the administrator account instead of the user login?
currently the report shows my windows domain administrator account login.
same for Top Application Users by Sessions
- Labels:
-
5.4
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is that account logged in to each machine? Are you running FortiClient on the machines?
Mike Pruett
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
we used this account to join the computer to domain during initial setup or during installation of software.
the clients on the bandwidth report are not installed with forticlient.
the report basically shows all users who have internet access using Internet bandwidth
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Probably best to have a look at the FortiGate first.
What does your FortiGate show the users as in it's own logs? The individual usernames or Administrator?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
fortigate also show only the Administrator instead of user names.
we configured our DNS server in fortigate DNS settings.
the DNS server is also our AD server.
does this makes sense
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is it possible that you have some scripts running under Administrator account frequently on the machines?
I saw a situation when a special account was listed all the time and the admin said that there is an account that checks the antivirus software udpate several times during the day.
We put this account into FSSO ignore list and the problem disappeared.
AtiT
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
the only thing i can think of is the sophos anti-virus definition updates.
we do not use FSSO.