Firewall Log Management · Panel › Alerts and Events

Alerts and Events: your firewall and izgate, in one feed.

Security events classified the moment they're queried from your firewall logs (IPS, virus, port scan, DDoS, failed login, VPN, configuration change, HA, blocked traffic) and izgate's own events (guest login, approval request/denial, panel actions, rule changes, device status) are presented on this page in a single unified feed.

  • Firewall + izgate events in a single list
  • Attack-source country map (FortiGate only)
  • KPIs with comparison to the previous window
Location
/alerts (Alerts and Events)
Classification
At query time, from firewall logs
Country data
FortiGate srccountry only
Export
Event list CSV
izgate Alerts and Events page: KPI cards, an event trend chart, event categories, an attack-source world map, and the events table
Alerts and Events: KPI cards, event trend, event categories, attack-source map, and events table
What's on the screen?

Top to bottom, what you see in the panel

  1. Title and time range: the "Alerts and Events" heading, preset time range buttons (15 min / 1 hr / 24 hr / 7 days / 30 days / Custom), a custom date range picker, and a "Refresh" button.
  2. KPI cards: Total events, Security, Firewall, Wi-Fi, and Blocked counts; each card has a small trend bar underneath and a percentage change compared with the previous window.
  3. Event Trend chart: a time series that separates the Security/Firewall/Wi-Fi/System categories by color.
  4. Event Categories: a donut chart showing each of those four categories' share of the total.
  5. Attack Sources map: the most frequent source countries in the selected window, marked on a world map with their counts; a ranked list by country sits alongside it.
  6. Filter row: Device, Event Type, Category, and Severity dropdowns, free-text Source IP and User fields, and text search within the event description.
  7. Events table: a total count in the header, a column picker, export, and an auto-refresh toggle; rows include time, severity, event type, device, source IP, destination, and user columns.
  8. Top Source IPs panel: a ranked list with an event-count bar for each IP.
What can you do?

Read firewall and izgate events together

Watch firewall security events

IPS, virus, web filter, application control, port scan, DDoS, failed login, VPN, configuration change, HA, and blocked traffic — all classified the moment they're queried and shown in the same list.

See izgate's own events too

Guest login/failed login, approval request/denial, panel login/failed login, panel configuration actions, rule changes, and device offline/online events are added to the same feed.

See attack sources on a map

Because FortiGate devices write country information into their logs, you can see the countries sending the most attacks on a map, with counts.

How to use it

Three steps to investigate an event

1

Review the time range and KPIs

Pick a preset range and see the change in total and per-category event counts.

2

Narrow with filters

Narrow the list by device, event type, category, severity, source IP, or user.

3

Inspect in the events table

List the relevant events in the table and export them if needed; turn on auto-refresh to watch the feed live.

Good to know

Limits and context

Attack-source country data comes only from FortiGate's srccountry field; other drivers (MikroTik, pfSense, Sophos, Palo Alto, generic syslog) don't yet have GeoIP enrichment for this (it's on the roadmap). System health notifications (a device that hasn't sent an event in the last 10 minutes, the parsing error rate, a backlog in the on-disk safe queue, pending guest requests) are collected separately via the bell icon in the top bar; don't confuse them with the event feed on this page.

Related features

Continue from Alerts and Events

Live Logs

Inspect the raw firewall record behind an event with detailed filters.

Devices

See the status behind a device's offline/online event.

Overview

See a summary of recent events and system health notifications on one screen.

Frequently asked questions

About Alerts and Events

What's the difference between Alerts and Events and Live Logs?

Live Logs shows raw firewall records; Alerts and Events classifies those records from a security angle and summarizes them together with izgate's own events (guest login, panel actions, etc.).

Which event types are classified?

IPS, virus, web filter, application control, port scan, DDoS, failed login, VPN, configuration change, HA, and blocked traffic; plus izgate's own events.

Does the attack-source country map work on all devices?

No, it's fed only by FortiGate's srccountry field; other drivers don't have this information yet.

Can I export events?

Yes, use "Export" on the Events table to download the list according to your selected filters.

See all questions

Making your network Law No. 5651 compliant is a one-day job.

Configure izgate Cloud based on your number of firewall devices and storage needs; no setup, get started in minutes. Call us with any questions.