Centralized log management
Set thresholds and create trigger-based alerting logic to automatically surface.
Quick Start Guide
Deploy Logmanager in your virtual environment
Authentication logs are often the fastest way to determine whether a configuration issue was caused by a normal administrative action or by something more suspicious. This workflow is useful for network investigations because it lets you review historical login activity quickly and narrow it to a specific switch and time period.
Open the log overview dashboard and filter for logs coming only from network switches. Then add another filter for successful logins so the result set contains authenticated access only.
Set the time interval to the period that matters for your investigation. In the example, the second week of November is selected so the results focus on the time around the suspected misconfiguration.
If suspicion is focused on one device, add that device as another filter. For example, narrowing the search to the headquarters switch makes it easier to review only access tied to that asset.
Add the username field or filter for it directly. If the results show only a known authorized user, that is a strong sign the incident was likely a normal mistake rather than malicious access.
How to Configure Logmanager Backups on an SMB Server
Backups are one of the most important parts of any Logmanager deployment. They help protect configuration,
How to Connect a FortiGate Firewall to Logmanager
Connecting FortiGate to Logmanager is useful because it centralizes traffic events, security logs, and operational activity
How to Create a FortiGate Configuration Change Alert in Logmanager
Alerting on firewall configuration changes is useful because these events often matter for both operations and
How to Integrate Logmanager with Flowmon
Flowmon is a network monitoring and security solution that provides deep visibility into network traffic using