Logs Search the logs
FortiAnalyzer Version 3.0 MR3 Administration Guide
05-30003-0082-20060925 85
Basic search
The basic search performs a simple search of all log files on the FortiAnalyzer
unit. The FortiAnalyzer unit maintains a search history for reference should you
need to use the search keywords again. The FortiAnalyzer searches all log files
and data for matches.
To perform a search, go to Log > Search. Enter the keywords for the search.
Separate multiple keywords with a space.
Search results appear below the search entry fields.
Advanced search
The advanced search provides more options to narrow your search criteria.
To perform an advanced search, go to Log > Search, and select Advanced
search.
Figure 29: FortiAnalyzer advanced search
Note: Searches using characters will not include results from the Traffic logs. Traffic logs
include information for source and destination IP addresses and ports which is strictly
numerical information.
For example, if you are searching on User1, you may get results for User1, however, none
of the results will include entries from the Traffic log. To get results from the traffic log, you
must search on the IP address of User1. For example, 10.10.10.1.
Search Select to begin searching the logs.
Basic search Select to perform a basic search.
Find results with all
of the words
Enter all the keywords you want to use in your search. The
FortiAnalyzer search engine will return all log entries that contain
all keywords entered. Separate keywords with a space.
Find results with at
least one of the
words
Enter all the keywords you want to use in your search. The
FortiAnalyzer search engine will return all log entries that contain
one or more of the keywords. Separate keywords with a space.
Find results without
the words
Enter the keywords that you do not want included in your search
results. If a log entry contains the keywords you are searching on
and includes a keyword from this field, the log entry will not be
included in the search results.
Log types Select the log types that you want to search. Hold the CTRL or
SHIFT keys to select multiple log types.
Devices Select the devices’ logs to search. Hold the CTRL or SHIFT keys
to select multiple devices.
Dated within Select a time frame of the log entries to search within.