Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
posix86749
New Contributor

FortiGate: Log filter in GUI

Hi, All

I Have Fortigate v6.0.5 build0268 (GA) (Virtual Appliance). And I have some problem with Forward Traffic log displaing.

I need to display events with particular address in destination field. For it I choose "destination" in filter and type in "somesite.com" (without quotes), but the list still shows all messages. It looks like filter not working. The same thing happens, when i choose "destination server" in filter options. 

What i'm doing wrong? What I need to do, to display events with particular address in destination field?

3 REPLIES 3
Toshi_Esumi
SuperUser
SuperUser

Destination filter takes only IP. If you open the log detail, you wouldn't see "somesite.com" in the log, even you might be seeing in the table under Destination column in parentheses. Either convert the URL to IP then use it for Destination filter or user something else like Application, which shows up in the log detail.

posix86749

Thanks gro your answer. 

But how can I filter log display if I need to show for wildcard destination address? For example, I need events, where in destination field there are present *microsoft.com, or *somesite*? Is it possible?

Toshi_Esumi

You can open a ticket at TAC to get a definitive answer. But I'm 90% sure you can't at least with the current GUI software because I believe the filters are simply filtering/matching log content literary with the "keys" you put in.  

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors