Centralized log management
Set thresholds and create trigger-based alerting logic to automatically surface.
Quick Start Guide
Deploy Logmanager in your virtual environment
Quick triage is useful when you receive an alert with very little context. A single IP address can still serve as a good investigation pivot. Logmanager makes this practical by allowing fast searching, column customization, and smooth expansion from one clue to a wider set of related events.
Open Discover and search for the suspicious IP address from the alert. Extend the time interval beyond the exact alert time so you can see what happened before and after the triggering event.
Add useful fields such as username, event type, and source device. This is helpful because it lets you understand the context of each event without opening every row one by one.
Review the timeline for failed logins, probing behavior, and later successful or application-related events. A sequence of failed attempts followed by valid activity can indicate escalating risk.
If multiple usernames or source systems appear in connection with the same IP address, continue by reviewing those users, other associated IPs, and any unusual access or privilege activity connected to them.
How to Configure Logmanager Backups on an SMB Server
Backups are one of the most important parts of any Logmanager deployment. They help protect configuration,
How to Connect a FortiGate Firewall to Logmanager
Connecting FortiGate to Logmanager is useful because it centralizes traffic events, security logs, and operational activity
How to Create a FortiGate Configuration Change Alert in Logmanager
Alerting on firewall configuration changes is useful because these events often matter for both operations and
How to Integrate Logmanager with Flowmon
Flowmon is a network monitoring and security solution that provides deep visibility into network traffic using