{"id":97707,"date":"2020-10-21T02:42:34","date_gmt":"2020-10-21T00:42:34","guid":{"rendered":"https:\/\/prohoster.info\/blog\/administrirovanie\/4-fortianalyzer-getting-started-v6-4-rabota-s-otchetami"},"modified":"2020-10-21T02:42:34","modified_gmt":"2020-10-21T00:42:34","slug":"4-fortianalyzer-getting-started-v6-4-rabota-s-otchetami","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/4-fortianalyzer-getting-started-v6-4-rabota-s-otchetami","title":{"rendered":"4. FortiAnalyzer Getting Started v6.4. Working with Reports","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"4. FortiAnalyzer Getting Started v6.4. Working with Reports\" src=\"\/wp-content\/uploads\/2020\/10\/8a75aa9e855f70d5f0c2d295e62cf0ac.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nHello, friends! In the <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/fortiservice\/blog\/523136\/\">previous lesson<\/a><\/noindex> we explored the basics of working with logs on FortiAnalyzer. Today we will go further and look at the key aspects of working with reports: what reports are, what they consist of, and how to edit existing reports and create new ones. As usual, we'll start with a bit of theory, followed by practical work with reports. Below is the theoretical part of the lesson, as well as a video tutorial that includes both theory and practice. <noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<p>The main purpose of reports is to consolidate large amounts of data contained in logs and present all the gathered information in a readable format: through graphs, tables, and charts. The picture below shows a list of pre-installed reports for FortiGate devices (not all reports are included, but I think it's already clear from this list that even 'out of the box' many interesting and useful reports can be generated). <\/p>\n<p><img decoding=\"async\" alt=\"4. FortiAnalyzer Getting Started v6.4. Working with Reports\" src=\"\/wp-content\/uploads\/2020\/10\/fa12b8af6927ac9530f75fc55d84acaf.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nHowever, reports only present the requested information in a readable format \u2014 they do not contain any recommendations for further action regarding identified issues. <\/p>\n<p>The main components of reports are charts. Each report consists of one or more charts. Charts determine what information needs to be extracted from the logs and in what format it should be presented. Datasets are responsible for extracting the information \u2014 SELECT queries to the database. It is in the datasets that it is precisely defined from where and what information needs to be extracted. Once the necessary data appears as a result of the query, formatting (or display) settings are applied to it. As a result, the obtained data is formatted into tables, graphs, or different types of charts. <\/p>\n<p>The SELECT query uses various commands that specify conditions for the information being extracted. The most important thing to keep in mind is that these commands must be applied in a specific order, and they are presented in that order below:<br \/>\nFROM \u2014 the only command that is mandatory in a SELECT query. It specifies the type of logs from which information needs to be extracted;<br \/>\nWHERE \u2014 this command sets conditions on the logs (for example, a specific application\/attack\/virus name);<br \/>\nGROUP BY \u2014 this command allows you to group information by one or more specified columns;<br \/>\nORDER BY \u2014 this command can be used to sort the output information by rows;<br \/>\nLIMIT \u2014 Limits the number of records returned by the query. <\/p>\n<p>FortiAnalyzer includes predefined templates for reports. The templates serve as what is known as a report layout \u2014 they contain the report text, its charts, and macros. With these templates, new reports can be created if minimal changes are required in the predefined ones. However, the predefined reports cannot be edited or deleted \u2014 they can be cloned, and necessary changes can be made to the copy. There is also the option to create custom report templates. <\/p>\n<p><img decoding=\"async\" alt=\"4. FortiAnalyzer Getting Started v6.4. Working with Reports\" src=\"\/wp-content\/uploads\/2020\/10\/06ccc5d523fc586c0defdece96d33f5c.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nSometimes you may encounter the following situation: a predefined report fits the task but not completely. You might need to add some information or, conversely, remove it. In this case, there are two options: clone and modify the template or the report itself. Here, several factors should be considered.<\/p>\n<p>Templates serve as a layout for the report, containing charts and the report text, no more than that. The reports themselves, in turn, besides the so-called 'layout,' include various report parameters: language, font, text color, generation period, data filtering, and so on. Therefore, if changes are needed only in the report layout, templates can be used. If additional report configuration is necessary, the report itself (or rather, its copy) can be edited. <\/p>\n<p>Based on templates, multiple similar reports can be created, so if many similar reports need to be made, it is preferable to use templates. <br \/>\nIf the predefined templates and reports do not suit you, it is possible to create either a new template or a new report. <\/p>\n<p><img decoding=\"async\" alt=\"4. FortiAnalyzer Getting Started v6.4. Working with Reports\" src=\"\/wp-content\/uploads\/2020\/10\/da6a2903adcfa57e710c4109db9f89bd.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nFortiAnalyzer also offers the ability to set up report forwarding to individual administrators via email or to upload them to external servers. This is done using the Output Profile mechanism. Separate Output Profiles are configured in each administrative domain. The following parameters are defined when configuring the Output Profile:<\/p>\n<ul>\n<li>The formats of the reports to be sent are PDF, HTML, XML, or CSV;<\/li>\n<li>The destination for the reports. This can be an administrator's email (for this, it is necessary to link FortiAnalyzer to the mail server, which we discussed in the previous lesson). It can also be an external file server \u2014 FTP, SFTP, SCP;<\/li>\n<li>It is possible to specify what to do with local reports that remain on the device after forwarding \u2014 either keep them or delete them. <\/li>\n<\/ul>\n<p>\nIf necessary, there is an option to speed up report generation. Let's consider two methods:<br \/>\nWhen creating a report, FortiAnalyzer builds charts from precompiled SQL cache data known as hcache. If hcache data has not been created during the report execution, the system must first create hcache and then build the report. This increases the report generation time. However, if new logs for the report are not received, the generation time for the report will significantly decrease upon re-execution, as the hcache data is already compiled. <\/p>\n<p>To improve report generation performance, you can enable automatic creation of hcache in the report settings. In this case, hcache is automatically updated upon arrival of new logs. An example of the setup is shown in the figure below. <\/p>\n<p>This process uses a large number of system resources (especially for reports that require a long time to gather data), so after enabling it, you need to monitor the status of FortiAnalyzer: whether the load has significantly increased, and if there is critical resource consumption. If FortiAnalyzer cannot handle the load, it is better to disable this process.<\/p>\n<p>It should also be noted that automatic updates of hcache data are enabled by default for scheduled reports. <\/p>\n<p>The second method to speed up report generation is grouping:<br \/>\nIf the same (or similar) reports are generated for different FortiGate devices (or other Fortinet devices), the report generation process can be significantly accelerated through grouping. Grouping reports can reduce the number of hcache tables and speed up the automatic caching time, thereby accelerating report generation.<br \/>\nIn the example shown in the diagram below, reports containing the string Security_Report in their title are grouped by the Device ID parameter.<\/p>\n<p><img decoding=\"async\" alt=\"4. FortiAnalyzer Getting Started v6.4. Working with Reports\" src=\"\/wp-content\/uploads\/2020\/10\/7dbd4a983596f4e61cbcb552b4f612dd.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nThe video tutorial presents the theoretical material discussed above, as well as practical aspects of working with reports\u2014from creating your own datasets and charts, templates, and reports to setting up report forwarding to administrators. Enjoy the viewing!<\/p>\n<p><center><iframe loading=\"lazy\" width=\"560\" height=\"315\" src=\"https:\/\/embedd.srv.habr.com\/iframe\/5f8f5889102304e11bb8d5ae\" frameborder=\"0\" allowfullscreen><\/iframe><\/center><\/p>\n<p>In the next lesson, we will explore various aspects of FortiAnalyzer administration and its licensing scheme. To not miss it, subscribe to our <noindex><a rel=\"nofollow\" href=\"https:\/\/www.youtube.com\/channel\/UCKOESE8nBWQPuQmi994_YMA\">YouTube channel<\/a><\/noindex>.<\/p>\n<p>You can also follow updates on the following resources:<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/vk.com\/fortiservice\">VK Group<\/a><\/noindex><br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/zen.yandex.ru\/id\/5c7d2162fa818600ae386a52\">Yandex Zen <\/a><\/noindex><br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/fortiservice.com\/\">Our website<\/a><\/noindex><br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/www.t.me\/tssolution\">Telegram channel<\/a><\/noindex><br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/fortiservice\/blog\/524128\/\">habr.com<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u0440\u0438\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u044e, \u0434\u0440\u0443\u0437\u044c\u044f! \u041d\u0430 \u043f\u0440\u043e\u0448\u043b\u043e\u043c \u0443\u0440\u043e\u043a\u0435 \u043c\u044b \u0438\u0437\u0443\u0447\u0438\u043b\u0438 \u043e\u0441\u043d\u043e\u0432\u044b \u0440\u0430\u0431\u043e\u0442\u044b \u0441 \u043b\u043e\u0433\u0430\u043c\u0438 \u043d\u0430 FortiAnalyzer. \u0421\u0435\u0433\u043e\u0434\u043d\u044f \u043c\u044b \u043f\u043e\u0439\u0434\u0435\u043c \u0434\u0430\u043b\u044c\u0448\u0435 \u0438 \u0440\u0430\u0441\u0441\u043c\u043e\u0442\u0440\u0438\u043c \u043e\u0441\u043d\u043e\u0432\u043d\u044b\u0435 \u0430\u0441\u043f\u0435\u043a\u0442\u044b \u0440\u0430\u0431\u043e\u0442\u044b \u0441 \u043e\u0442\u0447\u0435\u0442\u0430\u043c\u0438: \u0447\u0442\u043e \u0438\u0437 \u0441\u0435\u0431\u044f \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0442 \u043e\u0442\u0447\u0435\u0442\u044b, \u0438\u0437 \u0447\u0435\u0433\u043e \u043e\u043d\u0438 \u0441\u043e\u0441\u0442\u043e\u044f\u0442, \u043a\u0430\u043a\u0438\u043c \u043e\u0431\u0440\u0430\u0437\u043e\u043c \u043c\u043e\u0436\u043d\u043e \u0440\u0435\u0434\u0430\u043a\u0442\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0443\u044e\u0449\u0438\u0435 \u0438 \u0441\u043e\u0437\u0434\u0430\u0432\u0430\u0442\u044c \u043d\u043e\u0432\u044b\u0435 \u043e\u0442\u0447\u0435\u0442\u044b. \u041a\u0430\u043a \u043e\u0431\u044b\u0447\u043d\u043e, \u0441\u043d\u0430\u0447\u0430\u043b\u0430 \u043d\u0435\u043c\u043d\u043e\u0433\u043e \u0442\u0435\u043e\u0440\u0438\u0438, \u0430 \u043f\u043e\u0441\u043b\u0435 \u043f\u043e\u0440\u0430\u0431\u043e\u0442\u0430\u0435\u043c \u0441 \u043e\u0442\u0447\u0435\u0442\u0430\u043c\u0438 \u043d\u0430 \u043f\u0440\u0430\u043a\u0442\u0438\u043a\u0435. \u041f\u043e\u0434 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":97708,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-97707","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041f\u0440\u0438\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u044e, \u0434\u0440\u0443\u0437\u044c\u044f!\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/4-fortianalyzer-getting-started-v6-4-rabota-s-otchetami\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd474. FortiAnalyzer Getting Started v6.4. \u0420\u0430\u0431\u043e\u0442\u0430 \u0441 \u043e\u0442\u0447\u0435\u0442\u0430\u043c\u0438 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041f\u0440\u0438\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u044e, \u0434\u0440\u0443\u0437\u044c\u044f!\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/4-fortianalyzer-getting-started-v6-4-rabota-s-otchetami\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-10-21T00:42:34+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-10-21T00:42:34+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd474. FortiAnalyzer Getting Started v6.4. Working with Reports | ProHoster","description":"Hello, friends!","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/4-fortianalyzer-getting-started-v6-4-rabota-s-otchetami","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd474. FortiAnalyzer Getting Started v6.4. \u0420\u0430\u0431\u043e\u0442\u0430 \u0441 \u043e\u0442\u0447\u0435\u0442\u0430\u043c\u0438 | ProHoster","og:description":"\u041f\u0440\u0438\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u044e, \u0434\u0440\u0443\u0437\u044c\u044f!","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/4-fortianalyzer-getting-started-v6-4-rabota-s-otchetami","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-10-21T00:42:34+00:00","article:modified_time":"2020-10-21T00:42:34+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"97707","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 10:14:40","updated":"2022-10-03 07:08:53","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/97707","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=97707"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/97707\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/97708"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=97707"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=97707"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=97707"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}