Fortinet black logo

Administration Guide

Creating datasets

Creating datasets

FortiAnalyzer datasets are collections of data from logs for monitored devices. Charts and macros reference datasets. When you generate a report, the datasets populate the charts and macros to provide data for the report.

FortiAnalyzer has many predefined datasets that you can use right away. You can also create your own custom datasets.

To create a new dataset:
  1. If using ADOMs, ensure that you are in the correct ADOM.
  2. Go to Reports > Report Definitions > Datasets, and click Create New.
  3. Provide the required information for the new dataset.

    Name

    Enter a name for the dataset.

    Log Type

    Select a log type from the dropdown list.

    • The following log types are available for FortiGate: Application Control, Intrusion Prevention, Content Log, Data Leak Prevention, Email Filter, Event, Traffic, Virus, VoIP, Web Filter, Vulnerability Scan, FortiClient Event, FortiClient Traffic, FortiClient Vulnerability Scan, Web Application Firewall, GTP, DNS, SSH, and Local Event.
    • The following log types are available for FortiMail: Email Filter, Event, History, and Virus.
    • The following log types are available for FortiWeb: Intrusion Prevention, Event, and Traffic.

    Query

    Enter the SQL query used for the dataset. An easy way to build a custom query is to copy and modify a predefined dataset's query.

    Variables

    Click the Add button to add variable, expression, and description information.

    Test query with specified devices and time period

    Time Period

    Use the dropdown list to select a time period. When selecting Custom, enter the start date and time, and the end date and time.

    Devices

    Select All Devices or Specify to select specific devices to run the SQL query against. Click the Select Device button to add multiple devices to the query.

    Test

    Click to test the SQL query before saving the dataset configuration.

  4. Click Test.

    The query results are displayed. If the query is not successful, an error message appears in the Test Result pane.

  5. Click OK.

Creating datasets

FortiAnalyzer datasets are collections of data from logs for monitored devices. Charts and macros reference datasets. When you generate a report, the datasets populate the charts and macros to provide data for the report.

FortiAnalyzer has many predefined datasets that you can use right away. You can also create your own custom datasets.

To create a new dataset:
  1. If using ADOMs, ensure that you are in the correct ADOM.
  2. Go to Reports > Report Definitions > Datasets, and click Create New.
  3. Provide the required information for the new dataset.

    Name

    Enter a name for the dataset.

    Log Type

    Select a log type from the dropdown list.

    • The following log types are available for FortiGate: Application Control, Intrusion Prevention, Content Log, Data Leak Prevention, Email Filter, Event, Traffic, Virus, VoIP, Web Filter, Vulnerability Scan, FortiClient Event, FortiClient Traffic, FortiClient Vulnerability Scan, Web Application Firewall, GTP, DNS, SSH, and Local Event.
    • The following log types are available for FortiMail: Email Filter, Event, History, and Virus.
    • The following log types are available for FortiWeb: Intrusion Prevention, Event, and Traffic.

    Query

    Enter the SQL query used for the dataset. An easy way to build a custom query is to copy and modify a predefined dataset's query.

    Variables

    Click the Add button to add variable, expression, and description information.

    Test query with specified devices and time period

    Time Period

    Use the dropdown list to select a time period. When selecting Custom, enter the start date and time, and the end date and time.

    Devices

    Select All Devices or Specify to select specific devices to run the SQL query against. Click the Select Device button to add multiple devices to the query.

    Test

    Click to test the SQL query before saving the dataset configuration.

  4. Click Test.

    The query results are displayed. If the query is not successful, an error message appears in the Test Result pane.

  5. Click OK.