Running a FAZ-200D with 5.4.2, getting logs from a couple FortiGates, FortiAuthenticator, syslogs, etc. I've been getting some confusing results from my queries.
I keep getting empty results from certain queries in Log View, Custom View that should have non-empty results. The empty results often seem to be related to the sequence of specifiers.
For example, if I do a simple query for all denies of a certain subnet:
smart_action=_all_ source=IP.IP.IP.*
I will get a list that matches what I see in the logs. But if I make that query:
source=IP.IP.IP.* smart_action=_all_
I will either get a "No records found" or the the FAZ will display "Loading..." and never give results.
Using the right-mouse click on a log field to add to an existing query is even worse. Right clicking on a log entry with Action=Policy Violation gives me the option to add to the query search "Action = Policy Violation", which then adds smart_action="Policy Violation" to the query, which promptly tells me there are no entries found. Note that this works fine if there are not any other fields in the query.
Before I open a ticket on this, anybody have any suggestions?
Thanks in advance.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1660 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.