Hi all,
we have a fortigate 100D and we want to be able to extract navigation time from logs.
Is it possible?
We try to see log entries and look like this
date=2016-02-10 time=14:05:00 logid=0000000013 type=traffic subtype=forward level=notice vd=root srcip=192.168.0.103 srcport=62533 srcintf="lan" dstip=117.20.43.33 dstport=443 dstintf="wan1" sessionid=133112877 status=close policyid=1 dstcountry="Singapore" srccountry="Reserved" trandisp=snat transip=195.103.98.180 transport=62533 service=HTTPS proto=6 appid=41541 app="SSL_TLSv1.1" appcat="Network.Service" applist="default" duration=852 sentbyte=2205685 rcvdbyte=110032015 sentpkt=40358 rcvdpkt=78483 devtype="Windows PC" osname="Windows" osversion="7 (x64)" mastersrcmac=e4:68:a3:91:0b:c4 srcmac=e4:68:a3:91:0b:c4 utmaction=passthrough utmevent=app-ctrl attack="SSL" hostname="download.manageengine.com"
there is a duration token that in documentation says "time in second", is it right?
Maybe is possibile to create custum report in firewall to be able to do this?
Thanks
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1710 | |
1093 | |
752 | |
446 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.