on fortigate fortiview destinations are viewed as hostnames
how can i do so on the fortianalyzer im only getting destinations by ips
and im using 5.4 os on both
Hi,
right click in fortiview line you're interested in, and select "view related logs";
that action will take to a logview with full details for matched traffic
regards
/ Abel
If you want to resolve ip to hostname in FortiView, please try CLI:
config system fortiview setting
set resolve-ip enable
end
regards,
hz
If the destinations are showing on FGT as hostname & not FAZ, then you probably have the following setting on FGT (which only controls how info is displayed in the GUI): config log gui-display set resolve-host enable end
It is most accurate to do the DNS resolution before the logs are generated. That also ensures that neither FGT nor FAZ have to do any DNS resolution in the future (since it is recorded in the log).
config log setting set resolve-ip enable
end
Also, as recorded in the FortiAnalyzer Best Practices Guide, it is recommended not to perform DNS queries on the FortiAnalyzer if you are wishing to optimize report performance (see the section entitled "Report Performance").
User | Count |
---|---|
1883 | |
1141 | |
769 | |
447 | |
277 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.