跳转到内容
 
 

如果您想防止潜在的网络威胁演变成全面攻击,您需要定期监控日志。然而,每天手动筛选数百条日志以查找感兴趣的安全事件并非易事。我们全面的 日志管理解决方案EventLog Analyzer,可以简化整个过程。

EventLog Analyzer 可以收集 Fortinet 的 FortiGate 防火墙日志,进行分析,并生成图形报告,帮助您监控网络中发生的关键安全事件。

使用 EventLog Analyzer 监控 FortiGate 防火墙日志

使用 FortiGate 日志报告分析网络威胁

EventLog Analyzer 包含 预定义的图形报告,日志收集后即时生成。这些报告可以帮助您分析网络中的潜在安全威胁,并满足各种 合规法规,如 PCI DSSHIPAAGDPR。一旦发生合规违规,将立即生成警报。您还可以安排定期生成这些报告,并导出为 PDF 或 CSV 格式。

Fortinet日志分析器

以下是 EventLog Analyzer 为 Fortinet 设备生成的一些报告:

  • Fortinet 事件: The reports in this category provide information regarding all events taking place on Fortinet devices, along with their severity levels.

    可用报告: 所有事件 | 重要事件

  • 防火墙允许流量 | 防火墙拒绝流量: The reports in these two categories provide information regarding traffic that has been allowed or denied entry into the network. The traffic is categorized by source, destination, protocol, and port. Information about traffic trends is also included.

    可用报告: 允许流量 | 基于源的流量排行 | 基于协议的流量排行 | 基于端口的流量排行 | 允许流量趋势 | 拒绝连接 | 以及更多

  • 登录报告 | 登录失败报告: These two categories include reports regarding successful and failed logons, which are categorized by source IP address and username. The reports also include information on logon trends.

    可用报告: 登录 | 基于源的成功登录排行 | 基于用户的登录排行 | 登录趋势 | 登录失败 | 基于源的失败登录排行 | 基于用户的失败登录排行 | 登录失败趋势

    Fortinet日志分析器
  • VPN 登录报告 | VPN 登录失败报告: These two categories include reports regarding successful and failed VPN logons, which are categorized by remote device IP address and username. The reports also include information on VPN logon trends.

    可用报告: VPN 登出 | VPN 登录 | 基于远程设备的 VPN 登录排行 | 基于用户的 VPN 登录排行 | VPN 登录失败 | 基于用户的 VPN 登录失败排行 | 以及更多

  • 防火墙 IDS/IPS 报告: The reports in this category provide information regarding possible and critical attacks, which are classified by source IP address and destination IP address. The reports also include information on attack trends.

    可用报告: 可能攻击 | 严重攻击 | 攻击排行 | 基于源的攻击排行 | 基于目标的攻击排行 | 攻击趋势

  • 防火墙策略管理: These reports provide information regarding firewall policies that have been added, modified, or deleted.

    可用报告: 策略添加 | 策略修改 | 策略删除

  • 设备严重性报告: This category includes reports of various events based on their severity.

    可用报告: 紧急事件 | 警报事件 | 严重事件 | 错误事件 | 警告事件 | 通知事件 | 信息事件 | 调试事件

EventLog Analyzer 还允许您根据需求创建自定义报告。点击 这里 了解更多。

当可疑事件发生时,实时接收通知

利用 EventLog Analyzer 的 实时警报系统,最大限度减少检测和响应攻击所花费的时间。网络中出现任何威胁迹象时,警报将被触发,EventLog Analyzer 会立即通过电子邮件或短信通知您。

警报分为三个严重级别:注意、问题和严重。严重级别帮助您优先处理警报,以便立即修复最关键的问题。

Fortinet日志分析器

使用 EventLog Analyzer,您可以设置警报来监控 Fortinet 设备上的特定事件,如拒绝连接、登录失败、系统关机、策略修改和 VPN 登出。

Fortinet日志分析器

跟踪 Fortinet 设备中的活动。

下载

EventLog Analyzer 受信赖于

洛斯阿拉莫斯国家银行 密歇根州立大学
松下 Comcast
俄克拉荷马州立大学 IBM
埃森哲 美国银行
印孚瑟斯
安永

客户评价

  • 丹佛信用合作社使用 EventLog Analyzer 超过四年,用于内部用户活动监控。EventLog Analyzer 作为网络取证工具和合规尽职调查工具,提供了极大价值。该产品可以快速扩展以满足我们动态的业务需求。
    Benjamin Shumaker
    IT 副总裁 / ISO
    丹佛信用合作社
  • 我喜欢该应用程序的最大优点是结构良好的 GUI 和自动化报告。这对网络工程师在单一仪表板上监控所有设备非常有帮助。预设报告设计巧妙。
    Joseph Graziano, MCSE CCA VCP
    高级网络工程师
    Citadel
  • EventLog Analyzer 是我们信息技术需求中一个优秀的事件日志报告和警报解决方案。它减少了我们筛选事件日志的时间,并几乎实时提供管理员定义的警报通知。
    Joseph E. Veretto
    运营审查专家
    信息系统办公室
    佛罗里达州交通部
  • Windows事件日志和设备Syslogs是计算机或网络上发生情况的实时摘要。EventLog Analyzer是一款经济实用且易于使用的工具,通过推送实时和定时的警报与报告,让我了解网络中的动态。它是一款高级软件入侵检测系统应用。
    Jim Lloyd
    信息系统经理
    First Mountain 银行

奖项与认可

  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
综合日志管理的单一控制面板