Fortinet black logo

Handbook

Configuring fast reports

Configuring fast reports

Fast reports are real time statistics displayed on the Dashboard > Data Analytics page.

There are two ways to configure a fast report, through Log & Report orFortiView.

Before you begin:
  • You must have Read-Write permission for Log & Report settings.

After you have created a query configuration object, you can select it in the report configuration.

To configure fast reports through Log & Report:
  1. Go to Log & Report > Report Setting.
  2. Click the Fast Report tab.
  3. Click Create New to display the configuration editor.
  4. Complete the configuration as described in Fast report configuration.
  5. Save the configuration.
To configure fast reports through FortiView:
  1. Go to FortiView > Data Analytics.
  2. Click the Add Widget button in the far right. The Fast Report dialogue will display. It will be the same as in the Log & Report route.
  3. Complete the configuration as described in Fast report configuration.
  4. Save the configuration.

Fast report configuration

Settings Guidelines

Name

Configuration name. Valid characters are A-Z, a-z, 0-9, _, and -. No spaces. You reference this name in the zone configuration (if you use forwarders).

Note: After you initially save the configuration, you cannot edit the name.

Module

Select one of the following options:

  • SLB
  • Attack

SLB SubType

Select an option from the list menu:

  • Top Src
  • Top Dest
  • Top Browser
  • Top OS
  • Top Dev
  • Top Domain
  • Top URL
  • Top Referrer
  • Top Source Country
  • Top Session

Attack SubType

Select an option from the list menu:

  • Top Attack Type for All
  • Top Attack Type by VS for All
  • Top VS for DDoS
  • Top Destination Country for DDoS
  • Top VS for GEO
  • Top Source for GEO
  • Top Destination for GEO
  • Top Source Country for GEO
  • Top Destination Country for GEO
  • Top Action by Source for GEO
  • Top Action by Source Country for GEO
  • Top Category by VS for IP Reputation
  • Top Source for IP Reputation
  • Top Destination for IP Reputation
  • Top Source Country for IP Reputation
  • Top Destination Country for IP Reputation
  • Top Attack Type by VS for WAF
  • Top Attack Type by Source Country for WAF
  • Top Attack Type by Source for WAF
  • Top Attack by Destination Country for WAF
  • Top Attack by Destination for WAF
  • Top platform name by dest for AV
  • Top platform name by destcountry for AV
  • Top platform name by src for AV
  • Top platform name by srccountry for AV
  • Top platform name by vs for AV
  • Top reference by dest for AV
  • Top reference by destcountry for AV
  • Top reference by src for AV
  • Top reference by srccountry for AV
  • Top reference by vs for AV
  • Top src for IPS
  • Top srccountry for IPS

History Chart

Enable/Disable.

Time Range

Select an option from the list menu:

  • 10MINS
  • 1HOUR
  • 1DAY
  • 1WEEK
  • 1MONTH

Data Type

Select either of the following:

  • Bandwidth
  • Session

Configuring fast reports

Fast reports are real time statistics displayed on the Dashboard > Data Analytics page.

There are two ways to configure a fast report, through Log & Report orFortiView.

Before you begin:
  • You must have Read-Write permission for Log & Report settings.

After you have created a query configuration object, you can select it in the report configuration.

To configure fast reports through Log & Report:
  1. Go to Log & Report > Report Setting.
  2. Click the Fast Report tab.
  3. Click Create New to display the configuration editor.
  4. Complete the configuration as described in Fast report configuration.
  5. Save the configuration.
To configure fast reports through FortiView:
  1. Go to FortiView > Data Analytics.
  2. Click the Add Widget button in the far right. The Fast Report dialogue will display. It will be the same as in the Log & Report route.
  3. Complete the configuration as described in Fast report configuration.
  4. Save the configuration.

Fast report configuration

Settings Guidelines

Name

Configuration name. Valid characters are A-Z, a-z, 0-9, _, and -. No spaces. You reference this name in the zone configuration (if you use forwarders).

Note: After you initially save the configuration, you cannot edit the name.

Module

Select one of the following options:

  • SLB
  • Attack

SLB SubType

Select an option from the list menu:

  • Top Src
  • Top Dest
  • Top Browser
  • Top OS
  • Top Dev
  • Top Domain
  • Top URL
  • Top Referrer
  • Top Source Country
  • Top Session

Attack SubType

Select an option from the list menu:

  • Top Attack Type for All
  • Top Attack Type by VS for All
  • Top VS for DDoS
  • Top Destination Country for DDoS
  • Top VS for GEO
  • Top Source for GEO
  • Top Destination for GEO
  • Top Source Country for GEO
  • Top Destination Country for GEO
  • Top Action by Source for GEO
  • Top Action by Source Country for GEO
  • Top Category by VS for IP Reputation
  • Top Source for IP Reputation
  • Top Destination for IP Reputation
  • Top Source Country for IP Reputation
  • Top Destination Country for IP Reputation
  • Top Attack Type by VS for WAF
  • Top Attack Type by Source Country for WAF
  • Top Attack Type by Source for WAF
  • Top Attack by Destination Country for WAF
  • Top Attack by Destination for WAF
  • Top platform name by dest for AV
  • Top platform name by destcountry for AV
  • Top platform name by src for AV
  • Top platform name by srccountry for AV
  • Top platform name by vs for AV
  • Top reference by dest for AV
  • Top reference by destcountry for AV
  • Top reference by src for AV
  • Top reference by srccountry for AV
  • Top reference by vs for AV
  • Top src for IPS
  • Top srccountry for IPS

History Chart

Enable/Disable.

Time Range

Select an option from the list menu:

  • 10MINS
  • 1HOUR
  • 1DAY
  • 1WEEK
  • 1MONTH

Data Type

Select either of the following:

  • Bandwidth
  • Session