
FortiAnalyzer Version 3.0 MR3 Administration Guide
98
05-30003-0082-20060925
Users and groups
Forensic Analysis
Creating groups
Create user groups to obtain analysis information for a selection of users, rather
than running reports for a number of individuals. You must add individual users
before you can add them to a group.
To add a forensic analysis group
1
Go to
Forensic Analysis
>
Lookup
>
Group
.
2
Select Create New.
3
Enter the name of the group.
4
Select the users from the Available Users list, and select the right arrow to add
them to the group.
To remove a member, select a user from the Members list on the right and select
the left arrow.
5
Select OK.
Lookup
The Lookup provides a method of finding additional user information. For
example, if you know the user’s email address, you can use the lookup to find the
IP address or instant message user names. The User Lookup enables you to
have a complete user information base for forensic analysis reports.
To perform a user lookup, go to
Forensic Analysis
>
Lookup
>
Lookup
.
The following table describes what information you can find when you have partial
information.
Table 12: User lookup matrix
Lookup
Using
Result
IP address
Username
Returns all IP addresses where defined username
logged on.
Username
IP address
Returns all user names that logged on at the
defined address.
Email address
IP address
Returns all email originating from a defined
address.
IM name
IP address
Returns all IM names that logged on at a defined
IP address.
Summary of Contents for FortiAnalyzer-100A
Page 1: ...www fortinet com FortiAnalyzer Version 3 0 MR3 A D M I N I S T R A T I O N G U I D E...
Page 10: ...FortiAnalyzer Version 3 0 MR3 Administration Guide 10 05 30003 0082 20060925 Contents...
Page 88: ...FortiAnalyzer Version 3 0 MR3 Administration Guide 88 05 30003 0082 20060925 Log rolling Logs...
Page 138: ...FortiAnalyzer Version 3 0 MR3 Administration Guide 138 05 30003 0082 20060925 Output Alerts...
Page 161: ...www fortinet com...
Page 162: ...www fortinet com...