Are running muti-vdoms; If yes try the diag sys session command per-vdom, use filters ,etc....
http://socpuppet.blogspot.com/2013/06/diag-system-session-quick-way-find.html
http://socpuppet.blogspot.com/2014/09/exploring-diag-stats-fortigate.html
PCNSE
NSE
StrongSwan
Thank you, Emnoc, for the links to follow. The problem is that any command with "diag sys <whatever>" fails because there is no "diag sys" command. The second link did provide some help with the "diag stats" command but I have fewer options than what's listed on the links. Either way, diag status will offer some help. Thanks
UPDATE: It looks like I don't have privileged mode/enabled mode access to this FW. But I was able to use diag stats app-bandwidth to get the top 20 apps, then use diag stats app-usage-ip with the app ip from the previous command to get the IP addresses using the most bandwidth. This gives me what I need.
If there is a way to match the IP address with the machine name that would be ideal, but I can do that in Linux using the "nbstat" command.
User | Count |
---|---|
1883 | |
1141 | |
769 | |
447 | |
277 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.