Firewall Log Management · Panel › Logs

Live Logs: results in seconds across millions of rows.

Listed in the menu as "Logs" (formerly "5651 Records"), this page holds every row collected from your firewall in a column-based ClickHouse database; KPIs, multi-dimensional filters, a timeline and row-level detail all come together here.

  • Date, device, IP, user, MAC and text filters
  • Fast pagination for large result sets, default window now−duration … now+15 min
  • Rows restored from the archive are flagged
Location
Panel › Logs
Storage
Fast-search database
Pagination
Fast pagination for large result sets
View
KPI + filters + timeline + table
izgate Live Logs page: KPI cards, filters, a timeline and the log records table
Live Logs: KPI cards, filters, a timeline (24 hours) and the log records table
What's on screen?

Top to bottom, what you'll see in the panel

  1. Title and live toggle: the "Live Logs" heading, a "5651" tag, a "Live" on/off switch, "Pause," a time range picker and a "Refresh" button.
  2. KPI cards: Total, Traffic, System, VPN, Security and Blocked event counts; each card has a small trend sparkline underneath and the percentage change versus the previous period.
  3. Filter row: Device, Category and Action dropdowns; free-text fields for Source IP, Destination IP, NAT IP, User and MAC, plus a general text search box; below that, preset time-range buttons (15 min / 1 hr / 24 hr / 7 days / Custom), an "Unparsed only" toggle and a "Clear Filters" link.
  4. Timeline: a bar chart of the selected range, color-coded by category (Traffic/System/VPN/Identity).
  5. Log Records table: a "live stream active" indicator, a column picker, CSV download and display-setting buttons; rows show time, device, category, action, source/destination/NAT IP, user, URL/host and a detail column.
  6. Row detail panel: opens on the right when you click a record; it lists every field — time, device, category, action, source/destination/NAT IP and port, user (alias code plus resolved identity), MAC, URL/host, application, service/port, bytes sent/received, country and policy.
What can you do?

Answer a question with a single search

Filter across multiple dimensions

Combine time range, device, category, action, IPs, user, MAC, parsing errors and free text at once to find the record you're after.

Spot patterns on the timeline

Notice a sudden spike or an unusual quiet spell in the color-coded chart, then narrow the filters to that window.

Drill into row detail

Click a row to see every field, from source/destination and user to application, bytes and policy; the user's alias code is resolved to a person automatically.

Row detail panel on izgate's Live Logs page: source/destination IP, user, application, bytes and policy information
Log Detail panel: every field for a row opens in the right-hand panel
Log Detail panel

Select a row, see every field

The panel that opens on the right when you click a table row brings together time, device, category, action, source/destination/NAT IP and port, user, MAC, URL/host, application, service/port, bytes sent/received, country and policy in one place. Use the up/down arrows to move to the next or previous record.

  • User resolutionThe alias code (mg-xxxxxx) shown in the user field is resolved to the matching person in the panel.
  • Country informationComes only from FortiGate's srccountry field; it's left blank for other drivers.
How to use it?

Four steps to finding a record

1

Pick a time range

Choose one of the presets (15 min / 1 hr / 24 hr / 7 days) or set your own range with "Custom."

2

Narrow with filters

Fill in device, category, action, IP, user, MAC or free-text fields as needed.

3

Check the timeline and table

If you spot a spike on the timeline, zoom into that window and list the matching rows in the table.

4

Open the row detail

Click the record you want to examine and view every field in the right-hand panel; download it as CSV if needed.

What to know

Limits and context

Search runs on the fast-search database and uses fast pagination for large result sets; the default window is between now−duration and now+15 minutes. Country information comes only from FortiGate's srccountry field; other drivers don't have GeoIP enrichment yet (it's on the roadmap). If a firewall's license lapses, search and statistics on this page are hidden; log collection and archiving continue regardless.

Related features

Continue from Live Logs

Archive

The signed, timestamped home for records once they age out of the live window.

Alerts and Events

The same logs classified from a security angle and shown in a unified feed.

Devices

See which device is sending logs, its status, and the serial/address match.

Frequently asked questions

About Live Logs

What's this page called in the menu?

It appears as "Logs" in the panel menu; the page's former name was "5651 Records" (Panel › Logs).

How fast is the search?

Logs are kept in the fast-search database; even at millions of rows a day, filtered searches return results in milliseconds.

Do records restored from the archive show up on this screen?

Yes. Rows from segments restored to live from the Archive page become searchable in Live Logs too, and are also flagged as "restored."

Why does a code appear instead of a username?

Raw identity data (phone number/Turkish ID number) is never written to the firewall or the logs; every guest is assigned a fixed alias code (mg-xxxxxx). The panel automatically resolves this code to the person in the search and detail screens.

How do I find rows with parsing errors?

Turn on the "Unparsed only" toggle in the filter row to list the rows the driver couldn't recognize.

See all questions

Making your network Law No. 5651 compliant is a one-day job.

Configure izgate Cloud based on your number of firewall devices and storage needs; no setup, get started in minutes. Call us with any questions.