- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Fortigate Analyser - Traffic logs - Top Sources
Can anyone explain what is the Threat Score(Blocked/Allowed) and Sessions(Blocked/Allowed) in that Top Sources report.
How we can find Threat blocked/Allowed from logs. i.e which field in logs indicate the threat is blocked/Allowed.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Siva18,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Siva18,
As far as I am aware, threat score is a severity/risk score assigned by FortiAnalyzer to certain events occurring within your network. You should be able to view logs under Log & Report-> Threat Weight, according to a Reddit post asking similar questions.
These three articles may help you:
https://docs.fortinet.com/document/fortianalyzer/6.2.0/administration-guide/924197/threats-widgets
https://www.fortinetguru.com/2016/08/threats/
https://help.fortinet.com/fos60hlp/60/Content/FortiOS/fortigate-fortiview/Consoles/Threats.htm
I hope that helps! Feel free to get back to us if it doesn't answer your questions.
Kind regards,
