I’m fairly new to FortiAnalyzer and need to investigate if any users have accessed certain domains over the past several months. I have a list of domains and subdomains (e.g., example.com, sub.example.com, etc.), and in some cases I only have wildcard formats like *.example.com.
I need to find out:
Which user has accessed these domains Or which device/source IP generated the traffic or had any session with those domains.
What’s the best way to search in FortiAnalyzer using just domain names or wildcards?
Should I be looking in Web Filter logs, DNS logs, or Forward Traffic logs?
Thanks in advance.
In the log view, try use a filter like dst_domain="*.example.com"
User | Count |
---|---|
2546 | |
1354 | |
795 | |
643 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.