Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
digitaltrance
New Contributor II

Fortianalyzer Log View resolve destination IP

Hello all,

 

I am having  a hard time searching for and finding an answer for this question. I looked here and also reddit.

 

In FortiAnalyzer in Log View. Is there anyway to have the destination IP's resolve via DNS?

 

I have DNS configured and also enabled resolve-ip, no differences.

 

(setting)# show
config system fortiview setting
set resolve-ip enable
end

 

Any help would be great!

 

FortiAnalyzer 7.2

 

Thanks!

5 REPLIES 5
Rathan_FTNT
Staff
Staff

Hello,

 

Please verify if the below settings are enabled on Fortigate level
# config webfilter profile
    edit <profile-name>
        set log-all-url enable
        set extended-log enable
    end

EMEA TAC Engineer
digitaltrance

What if you are not using the web filter profiles/web filter inspection?

 

 

EEHC

I hope we meet for an installation.

EEHC
EEHC
EEHC

"I am having  a hard time searching for and finding an answer" we are all so. You nad my smile in a difficult time.

Please check this,. I hope it helps

config log setting
set resolve-ip disable
set resolve-port enable
set log-user-in-upper disable
set fwpolicy-implicit-log disable
set fwpolicy6-implicit-log disable
set log-invalid-packet disable
set local-in-allow enable
set local-in-deny-unicast enable
set local-in-deny-broadcast enable
set local-out enable
set local-out-ioc-detection enable
set daemon-log disable
set neighbor-event disable
set brief-traffic-format disable
set user-anonymize disable
set expolicy-implicit-log disable
set log-policy-comment disable
set rest-api-set disable
set rest-api-get disable
end

 

 

Here is a reference:

https://docs.fortinet.com/document/fortigate/6.2.1/cli-reference/382620/log-setting

EEHC
EEHC
EEHC
Contributor

"config system fortiview setting"

I use "?" in CLI and it helps in expecting the place where I may go.

 

FortiGate01 # conf log
custom-field Configure custom log fields.
disk Configure disks.
eventfilter Configure log event filters.
fortianalyzer Configure first FortiAnalyzer device.
fortianalyzer-cloud Configure cloud FortiAnalyzer device.
fortianalyzer2 Configure second FortiAnalyzer device.
fortianalyzer3 Configure third FortiAnalyzer device.
fortiguard Configure log for FortiCloud.
gui-display Configure how log messages are displayed on the GUI.
memory Configure memory log.
null-device Configure logging for statistics collection for when no external logging destination, such as FortiAnalyzer, is present (data is not saved).
setting Configure general log settings.
syslogd Configure first syslog device.
syslogd2 Configure second syslog device.
syslogd3 Configure third syslog device.
syslogd4 Configure fourth syslog device.
tacacs+accounting tacacs+accounting
tacacs+accounting2 tacacs+accounting2
tacacs+accounting3 tacacs+accounting3
threat-weight Configure threat weight settings.
webtrends Configure Web trends.

 

From a point like this, you guess different directions to check. Then try them and you will find your goal.

EEHC
EEHC
Labels
Top Kudoed Authors