Watch firewall security events
IPS, virus, web filter, application control, port scan, DDoS, failed login, VPN, configuration change, HA, and blocked traffic — all classified the moment they're queried and shown in the same list.
Security events classified the moment they're queried from your firewall logs (IPS, virus, port scan, DDoS, failed login, VPN, configuration change, HA, blocked traffic) and izgate's own events (guest login, approval request/denial, panel actions, rule changes, device status) are presented on this page in a single unified feed.
IPS, virus, web filter, application control, port scan, DDoS, failed login, VPN, configuration change, HA, and blocked traffic — all classified the moment they're queried and shown in the same list.
Guest login/failed login, approval request/denial, panel login/failed login, panel configuration actions, rule changes, and device offline/online events are added to the same feed.
Because FortiGate devices write country information into their logs, you can see the countries sending the most attacks on a map, with counts.
Pick a preset range and see the change in total and per-category event counts.
Narrow the list by device, event type, category, severity, source IP, or user.
List the relevant events in the table and export them if needed; turn on auto-refresh to watch the feed live.
Attack-source country data comes only from FortiGate's srccountry field; other drivers (MikroTik, pfSense, Sophos, Palo Alto, generic syslog) don't yet have GeoIP enrichment for this (it's on the roadmap). System health notifications (a device that hasn't sent an event in the last 10 minutes, the parsing error rate, a backlog in the on-disk safe queue, pending guest requests) are collected separately via the bell icon in the top bar; don't confuse them with the event feed on this page.
Live Logs shows raw firewall records; Alerts and Events classifies those records from a security angle and summarizes them together with izgate's own events (guest login, panel actions, etc.).
IPS, virus, web filter, application control, port scan, DDoS, failed login, VPN, configuration change, HA, and blocked traffic; plus izgate's own events.
No, it's fed only by FortiGate's srccountry field; other drivers don't have this information yet.
Yes, use "Export" on the Events table to download the list according to your selected filters.
Configure izgate Cloud based on your number of firewall devices and storage needs; no setup, get started in minutes. Call us with any questions.