Hi Guys,
I am using a Fortigate 900D on which I can see the logs of config changes by administrators by filtering on the log ID's 44544, 44545, 44546 and 44547.
We are also using a Fortianalyzer 400E on which I am trying to run a report to match on system events to match on cfgattr; cfgobj; and cfgpath but nothing is shown after running the report. All event logs are being sent to the FAZ. I have attached a screenshot of the Forti and the FAZ.
Any help would be most welcome!
Thanks,
Jonathan
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I don't see any values set in your 3 filters. Could that be the problem? From the log view, once you have the data filtered to your liking, save the query which you can then use in a report.
HTH
d
Thanks,
I solved it by creating a dataset which pulls from the log and then created a chart that uses that dataset.
I found the following post very helpful https://forum.fortinet.com/tm.aspx?m=144882
:)
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1711 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.