Fortinet black logo

Administration Guide

Starting a global search

Starting a global search

To perform a simple global search, use the default values for the search federation, cluster and log time, then select a log type.

To perform a simple search:
  1. Select a search federation. Default” is the default.
  2. Select a cluster. LocalCluster is the default.
  3. Select the log time. Last 1 hour is the default.
  4. Select the log type. For example, FortiGate Traffic.
  5. (Optional) Select the log labels filter.
  6. Click Run Query to start a search.

Global Search settings

The following image and the corresponding to table provide information about each of the Global Search settings.

Search setting Description

1

Search Federation dropdown

Click the dropdown menu to select a federation. The default is Default.

2

Time Range selection

Click the dropdown menu to select a time range. The default is Last 1 hour.

3

Run Query Click Run Query to start the search.

4

Server Click the dropdown to select a server. The default is Local Cluster.

5

Log Type Click the dropdown to select a log type.

6

Log Label Click the dropdown to select a log label.

7

Log Query Input Use this field to enter the log query.

8

Histogram Displays the log time-range.

9

Log details Displays the log details.

Starting a global search

To perform a simple global search, use the default values for the search federation, cluster and log time, then select a log type.

To perform a simple search:
  1. Select a search federation. Default” is the default.
  2. Select a cluster. LocalCluster is the default.
  3. Select the log time. Last 1 hour is the default.
  4. Select the log type. For example, FortiGate Traffic.
  5. (Optional) Select the log labels filter.
  6. Click Run Query to start a search.

Global Search settings

The following image and the corresponding to table provide information about each of the Global Search settings.

Search setting Description

1

Search Federation dropdown

Click the dropdown menu to select a federation. The default is Default.

2

Time Range selection

Click the dropdown menu to select a time range. The default is Last 1 hour.

3

Run Query Click Run Query to start the search.

4

Server Click the dropdown to select a server. The default is Local Cluster.

5

Log Type Click the dropdown to select a log type.

6

Log Label Click the dropdown to select a log label.

7

Log Query Input Use this field to enter the log query.

8

Histogram Displays the log time-range.

9

Log details Displays the log details.