FortiView Top Source and Top Destination Firewall Objects monitors
The FortiView Source Firewall Objects and FortiView Destination Firewall Objects monitors leverage UUID to resolve firewall object address names for improved usability.
Requirements
To have a historical Firewall Objects-based view, address objects' UUIDs need to be logged.
To enable address object UUID logging in the CLI:
config system global
set log-uuid-address enable
end
To add a firewall object monitor in the GUI:
-
Click Add Monitor. The Add Monitor window opens.
-
In the Search field, type Destination Firewall Objects and click the Add button next to the dashboard name.
-
In the FortiGate area, select the FortiGate(s) from the dropdown.
-
In the Data Source area, select Best Available Device or Specify. For information, see Using the FortiView interface.
-
From the Time Period dropdown, select the time period. Select now for real-time information, or (1 hour, 24 hours, and 7 days) for historical information.
-
From the Sort By dropdown, select Bytes, Sessions, Bandwidth, or Packets.
-
Click OK. The monitor is added to the tree menu.
To drill down Firewall Objects:
-
Open the FortiView Source Firewall Objects or FortiView Destination Firewall Objects monitor.
-
Select any source or destination object and click Drill down.
-
Click the tabs to sort the sessions.
-
Select an entry, then click View session logs to view the session logs.