Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mh_mw
New Contributor

fortiview:destinations as hostnames

on fortigate fortiview destinations are viewed  as hostnames 

how can i do so on the fortianalyzer im only getting destinations by ips 

and im using 5.4 os on both 

4 REPLIES 4
abelio
Valued Contributor

Hi,

right click in fortiview line you're interested in, and select "view related logs";

that action will take to a logview with full  details for matched traffic

 

 

regards




/ Abel

regards / Abel
hzhao_FTNT

If you want to resolve ip to hostname in FortiView, please try CLI:

config system fortiview setting

set resolve-ip enable

end

 

regards,

hz

 

 

chall_FTNT

If the destinations are showing on FGT as hostname & not FAZ, then you probably have the following setting on FGT (which only controls how info is displayed in the GUI): config log gui-display set resolve-host enable end

 

It is most accurate to do the DNS resolution before the logs are generated.  That also ensures that neither FGT nor FAZ have to do any DNS resolution in the future (since it is recorded in the log).

 

config log setting set resolve-ip enable

end

Chris Hall
Fortinet Technical Support
chall_FTNT

Also, as recorded in the FortiAnalyzer Best Practices Guide, it is recommended not to perform DNS queries on the FortiAnalyzer if you are wishing to optimize report performance (see the section entitled "Report Performance").

 

Chris Hall
Fortinet Technical Support
Labels
Top Kudoed Authors