I have a configured File Filter, logs go to Forti Analyzer. For example, I have a monitor for PDF files, I see which documents are sent and received by users according to my rule. But in the case when an incident occurs (conditional data leak) how would I be able to check which user sent document X? Most of all I am interested in viewing the documents that FortiGate has recorded (Yes, I see that someone has sent a document, but I don't know what is inside, I can't look at it). How can this be solved?
Hello usernamer,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hello,
We are still looking for someone to help you.
We will come back to you ASAP.
Regards,
Hello,
Could you please indicate to us which firmware version are you using?
Thanks a lot in advance,
Hi,
I understand that you want to read the document which is logged by your FGT file filter.
While the FortiGate firewall can record that a document was sent, it does not store the content of the document itself. To view the content of the document, you may need to rely on other security measures such as Data Loss Prevention solutions, email archiving systems, or endpoint security solutions that provide document inspection capabilities.
You may reach out to your regional sales team who might be able to guide you based on your requirement.
BR,
Manosh
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1759 | |
1116 | |
766 | |
447 | |
242 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.