Fortinet black logo

Administration Guide

Audit reports

Audit reports

User audit reports can be generated in order to comply with audit requirements. These reports include various attributes for all users configured on the FortiAuthenticator.

Users audit

To generate and download user audit reports, go to Logging > Audit Reports > Users Audit and select Download. A CSV format file will be saved to the computer.

The following attributes are included in the .csv file:

username Username.
user type Set to either local, ldap, or radius.
remote server name Set to either ldap or radius, or empty for local.
first name User's first name.
last name User's last name.
email address User's email address.
active Set to either t for true/enabled or f for false/disabled.
role Set to either user, sponsor, or administrator.
admin profile

One of the following:

  • Set to full if role is set to administrator with full permissions.
  • Set to their admin profile names separated by "/" for multiple profiles (e.g. logging/saml) if role is set to administrator without full permissions.
  • Empty is role is set to either user or sponsor.
created Date and time of account creation.
last used Date and time of last login.
token type Type of token-based authentication.
token info Token information.

Audit reports

User audit reports can be generated in order to comply with audit requirements. These reports include various attributes for all users configured on the FortiAuthenticator.

Users audit

To generate and download user audit reports, go to Logging > Audit Reports > Users Audit and select Download. A CSV format file will be saved to the computer.

The following attributes are included in the .csv file:

username Username.
user type Set to either local, ldap, or radius.
remote server name Set to either ldap or radius, or empty for local.
first name User's first name.
last name User's last name.
email address User's email address.
active Set to either t for true/enabled or f for false/disabled.
role Set to either user, sponsor, or administrator.
admin profile

One of the following:

  • Set to full if role is set to administrator with full permissions.
  • Set to their admin profile names separated by "/" for multiple profiles (e.g. logging/saml) if role is set to administrator without full permissions.
  • Empty is role is set to either user or sponsor.
created Date and time of account creation.
last used Date and time of last login.
token type Type of token-based authentication.
token info Token information.