Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jilljrm
New Contributor

report config with 200D

I just upgraded from 100B to 200D, and I can' t seem to get the report filter right. I want to isolate just my servers, specify by IP address, and create reports to examine outgoing traffic & incoming traffic. Nothing I have tried so far works. With the 100B I used IP addresses as Source, but when I transfer this info to src_int on the 200D, I get null results. All the documentation seems to refer to the 100B format rather than the 200D format. I expected problems, but I' ve run out of ideas. thanks, Jill
6 REPLIES 6
AtiT
Valued Contributor

Hi jilljrm, Your post is in section for FortiAnalyzer. Are you sending the logs to analyzer? If yes what is the FW version of your analyzer? If you are trying to generate logs on the fortigate it seems to me that you have a bad filter set. " src_int" is the source interface not IP.

AtiT

AtiT
jilljrm
New Contributor

Yes I am sending logs from a Fortigate 300C to a FortiAnalyzer 200D, whose report config is quite different from my old FortiAnalyzer 100B. On the 100B, I was able to pass a list of IP addresses to the Source field in the data filter, in order to examine the outgoing traffic from a specific set of servers. I am trying to reproduce this on the 200D. thanks, Jill
AtiT
Valued Contributor

Hi, When I set a filter for the report is working for me.

AtiT

AtiT
jilljrm
New Contributor

Unfortunately I don' t have that option in my report config. OS 4.0 MR3 Patch 6, index-based logging. Would it be possible to build custom filters in the CLI? I can' t find any documentation that matches what I am seeing on my admin console. thanks, Jill
AtiT
Valued Contributor

Hi, I am not sure but probably no one can help as almost everybody using some of the 5.x version. Documentation can be found on http://docs.fortinet.com Instead of FortiGate/FortiOS select FortiAnalyzer and then the mayor version. After that you can switch between Admin guides, Reference manuals etc.

AtiT

AtiT
emorillo
New Contributor II

For v5.0: I had too many IPs and " departments" (groups) to try and filter them in the report, what I ended up doing was setting up policies in the FortiGate to group the addresses I wanted, then I filtered the report by policy ID. (4, 10, 35, 38, 39, etc) The old version of FortiAnalyzer (I have one of them still running 4.0 MR3 Patch 5) had a specific place to set up filters (Report>Config>Data Filter) this definitely made things easier.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors