I have a Fortigate 30e with Webfiltering and FortiClient EMS server with Webfiltering (small shop)
No FortiAnalyzer
No AD or user integration
No explicit proxy in clients / browsers

I would like to report on all traffic, or at least web 80/443 to begin with
Date time
Source IP and host name (internal reverse DNS…?)
Dest IP and domain
URL (if web traffic)

Is there a way to parse the logs that are already being collected into a readable/usable format? After the investment already made and having 2 tools that filter web traffic, I would rather not pay huge $$ for a report reader…

2 Spice ups

You probably should look into syslog function, to send those entries to a log aggregator/analyzer like Splunk, Logentries, ELK, Kiwi etc. There are a lot of options depending on log volume, cost, ease of use. I have a free Splunk instance that I use for only small amounts of logs when debugging.

You should check if Forticloud his enough for your need.

1 Spice up

Forticloud is very much what I am looking for! Thanks! Is there a way to convert Source and Destination IP’s to names?

Seem that it doesn’t. I do get username, but not the computer one.

Anyone know how to get name resolution on these reports? @bishop19 and I would love to know!

Seem like we are out of luck on this one : Workstation Hostnames in Logs - Fortinet Community , except if we pay for Forticloud…