Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Jond
New Contributor III

Disappointed ... reporting etc.

Hi all, I' m finding my new shiny Fortianalyser rather impenetrable. The default reports are worse than useless and I find myself really rather disappointed compared to a standard old syslog server! I wonder whether some of the knowledgeable people here could answer a few questions? - is it possible to just run SQL queries directly and receive the output ? (or does it have to be integrated into a chart/report etc.) - is there a guide to using SQL on the Fortianalyzer somewhere? - is there a schema somewhere to know what columns I might even use? Sort of questions I want to answer are... - which user accessed a specific/host/ip address and when - what traffic is being exchanged between specific ip addresses etc. etc. I' m sure there will be more :-) Thanks, Jon
24 REPLIES 24
RafalS
New Contributor

Hey Fellows, So desirable thread, I ended up with v5.0.7. While the two-dimensional reports seem to be +/- under control, I wonder if more complex charts - similar to what I' ve seen in my Fortigate (local reports of users detailed activity) or what can be achieved through a drill-down can be obtained. Now we can have a report based on predefined charts: Top Users by Sessions Top Destination by Sessions Top Applications by Sessions Sometimes a report combining at least two, maybe three of the above charts would be handy: Top User 1 by sessions -Top Dst IP 1 (for User 1) by sessions --Top Application 1 (for User 1 and Dst IP 1) by sessions --Top Application 2 (for User 1 and Dst IP 1) by sessions --Top Application N (for User 1 and Dst IP 1) by sessions -Top Dst IP 2 (for User 1) .... Do you believe it' s doable at all? Thank you, Rafal
FCNSP 4.x running FortiOS 5.0.4 on FG621B A-A HA
FCNSP 4.x running FortiOS 5.0.4 on FG621B A-A HA
FatalHalt

if I backup my reports will my output profiles also be be backed up and replaced?
Long story short, not with my experience. When we went to 5.0.6, we had to recreate all output profiles.
lopri1
New Contributor

I had to recreate / clone 400 + reports and 400 + output profiles because migrating from 4.3.8 to 5.0.6 did not support the output profiles and reports are done entirely different now. I painfully made it through that and everything seemed to be working fine but then I upgraded to 5.0.7 and now my reports are not working....sigh... Anyway my question if anyone knows is: if I backup my reports will my output profiles also be be backed up and replaced? I think I' m going to need to flash and reinstall 5.0.7 but I am afraid I will lose all my work in reports and output profiles...
Richard
Richard
jrpayne
New Contributor

I am also very disappointed with my FAZ. The reporting is not useful. I have been trying forever to get answers about some of it. For example, we frequently get requests from managers for an employee' s web browsing history for the past month. I have that some of those reports appear to be incriminating when in fact they are not. Let' s say that I give a manger a report that says the user visited Facebook or made an attempt to go to Facebook when in fact, they may have browsed a site that had a link to some Facebook material. So now you have an employee that cant explain to their manager why that is on their report and managers that are not educated enough to know how that can happen. In my environment, there needs to be a way to differentiate between things like that. We are a county government and things like that can get a person disciplined or worse. The closest thing, I have ever seen to that was when in the reports, you could specify " Web Clicks Only" which was determined by the amount of time spent there. Now I guess there is nothing. If there is something like that, I would love to know about it.
L_FTNT

Hi jrpayne, You have a very valid use case there. It might be good for you to start a new thread just focusing on how to improve the web browsing report. In my opinion, this thread is getting too long, touches many issues and it has lost its focus. LC
Ling Lu
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors