Centralized log management
Set thresholds and create trigger-based alerting logic to automatically surface.
Quick Start Guide
Deploy Logmanager in your virtual environment
Suspicious cloud logins rarely exist in isolation. This workflow is useful because it shows how to pivot from an Office 365 alert into broader on-premises and cross-system activity. That makes it easier to determine whether the event is harmless, user-related, or part of a larger compromise.
Open the Office 365 overview dashboard and filter for alerts tagged as notified. Then open the specific log entry tied to the suspicious login. This gives you the username and source IP address needed for the next steps.
Filter for all activity from the suspicious IP address and remove filters that limit the view only to alerted events. This makes it possible to see the broader context, including activity that did not itself trigger an alert.
If the same source IP is tied to more than one username, investigate every related account. In the example, one of the users deleted many files, which immediately raises the severity of the incident.
Copy the suspicious username and switch to the general log overview dashboard. Review all related actions in other systems, including Windows. Look for account creation, password resets, account enabling, or adding users to groups, as these may indicate privilege escalation or persistence.
How to Configure Logmanager Backups on an SMB Server
Backups are one of the most important parts of any Logmanager deployment. They help protect configuration,
How to Connect a FortiGate Firewall to Logmanager
Connecting FortiGate to Logmanager is useful because it centralizes traffic events, security logs, and operational activity
How to Create a FortiGate Configuration Change Alert in Logmanager
Alerting on firewall configuration changes is useful because these events often matter for both operations and
How to Integrate Logmanager with Flowmon
Flowmon is a network monitoring and security solution that provides deep visibility into network traffic using