Filter across multiple dimensions
Combine time range, device, category, action, IPs, user, MAC, parsing errors and free text at once to find the record you're after.
Listed in the menu as "Logs" (formerly "5651 Records"), this page holds every row collected from your firewall in a column-based ClickHouse database; KPIs, multi-dimensional filters, a timeline and row-level detail all come together here.
Combine time range, device, category, action, IPs, user, MAC, parsing errors and free text at once to find the record you're after.
Notice a sudden spike or an unusual quiet spell in the color-coded chart, then narrow the filters to that window.
Click a row to see every field, from source/destination and user to application, bytes and policy; the user's alias code is resolved to a person automatically.
The panel that opens on the right when you click a table row brings together time, device, category, action, source/destination/NAT IP and port, user, MAC, URL/host, application, service/port, bytes sent/received, country and policy in one place. Use the up/down arrows to move to the next or previous record.
mg-xxxxxx) shown in the user field is resolved to the matching person in the panel.srccountry field; it's left blank for other drivers.Choose one of the presets (15 min / 1 hr / 24 hr / 7 days) or set your own range with "Custom."
Fill in device, category, action, IP, user, MAC or free-text fields as needed.
If you spot a spike on the timeline, zoom into that window and list the matching rows in the table.
Click the record you want to examine and view every field in the right-hand panel; download it as CSV if needed.
Search runs on the fast-search database and uses fast pagination for large result sets; the default window is between now−duration and now+15 minutes. Country information comes only from FortiGate's srccountry field; other drivers don't have GeoIP enrichment yet (it's on the roadmap). If a firewall's license lapses, search and statistics on this page are hidden; log collection and archiving continue regardless.
The signed, timestamped home for records once they age out of the live window.
The same logs classified from a security angle and shown in a unified feed.
See which device is sending logs, its status, and the serial/address match.
It appears as "Logs" in the panel menu; the page's former name was "5651 Records" (Panel › Logs).
Logs are kept in the fast-search database; even at millions of rows a day, filtered searches return results in milliseconds.
Yes. Rows from segments restored to live from the Archive page become searchable in Live Logs too, and are also flagged as "restored."
Raw identity data (phone number/Turkish ID number) is never written to the firewall or the logs; every guest is assigned a fixed alias code (mg-xxxxxx). The panel automatically resolves this code to the person in the search and detail screens.
Turn on the "Unparsed only" toggle in the filter row to list the rows the driver couldn't recognize.
Configure izgate Cloud based on your number of firewall devices and storage needs; no setup, get started in minutes. Call us with any questions.