Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
njira
New Contributor

How to search FortiAnalyzer logs for specific domains or wildcards?

I’m fairly new to FortiAnalyzer and need to investigate if any users have accessed certain domains over the past several months. I have a list of domains and subdomains (e.g., example.com, sub.example.com, etc.), and in some cases I only have wildcard formats like *.example.com.

I need to find out:

Which user has accessed these domains Or which device/source IP generated the traffic or had any session with those domains.

What’s the best way to search in FortiAnalyzer using just domain names or wildcards?

Should I be looking in Web Filter logs, DNS logs, or Forward Traffic logs?

Thanks in advance.

https://9apps.ooo/
1 REPLY 1
AEK
SuperUser
SuperUser

In the log view, try use a filter like dst_domain="*.example.com"

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors