Viewing the Audit log
To view the Audit log, follow these steps.
The Audit log displays log entries for the length of your tenant's event retention period. By default, this is 30 days. |
How to view the Audit log
- In the FortiDLP Console, on the left-hand sidebar, click .
- Under General, select the Audit log tab.
Log entries for the current day are shown. - Click a log entry to view its related details.
- Optionally, do the following:
- To filter log entries by time, click the time selector and set your preferred time range:
- To filter using a time preset, click one of the following options:
- Last 60 min
- Today
- Last 24 hours
- Last 7 days
- Last 30 days.
- To filter using custom time frame:
- In the From fields, type or select the start date and time.
- In the To fields, type or select the end date and time.
- Click Apply.
- To filter using a time preset, click one of the following options:
- To filter log entries by type:
- Click the Log event type column.
- Select the checkbox(es) for the log event types you want to view.
- Scroll to the bottom of the dialog box and click Apply.
- To filter log entries by a property value using a quick filter:
- In the relevant log entry panel, hover over the value and either click to execute an equals search (returning log entries that contain this value) or click to execute a does not equal search (returning log entries that do not contain this value) .
Multiple filters can be used to perform AND searches. OR searches are not supported. To add another filter, repeat this step.
- In the relevant log entry panel, hover over the value and either click to execute an equals search (returning log entries that contain this value) or click to execute a does not equal search (returning log entries that do not contain this value) .
- To filter log entries by a specific property value using the search bar:
- Click the search bar.
- Type the property name. The search is case sensitive.
- Select or type one of the following operators:
- = (equals).
- != (does not equal).
- Type the value.
When filtering by the value of a nested property, you must separate path elements with a period. Referring to the following example, to search for log entries associated with the operator Karen Jones, you would enter
auth.operator_display_name=Karen Jones
. - Press Enter or click Search now.
Multiple filters can be used to perform AND searches. OR searches are not supported. To add another filter, click the search bar and repeat the steps above.
Log entries matching your criteria are shown.
- To export the Audit log, see Exporting the Audit log.
- To filter log entries by time, click the time selector and set your preferred time range: