Fortinet 3.0 MR7 Network Card User Manual


 
Network Analyzer Searching the Network Analyzer logs
FortiAnalyzer Version 3.0 MR7 Administration Guide
05-30007-0082-20080908 151
Searching the Network Analyzer logs
You can search the Network Analyzer log files for matching text using two search
types: Quick Search and Full Search.
You can use Quick Search to find results more quickly if your search terms are
relatively simple and you only need to search indexed log fields. Indexed log fields
are those that appear with a filter icon when browsing the logs in column view;
unindexed log fields do not contain a filter icon for the column or do not appear in
column view, but do appear in the raw log view. Quick Search keywords cannot
contain:
special characters such as single or double quotes ( or ) or question
marks (?)
wild card characters (*), or only contain a wild card as the last character of a
keyword (logi*)
You can use Full Search if your search terms are more complex, and require the
use of special characters or log fields not supported by Quick Search. Full Search
performs an exhaustive search of all log fields, both indexed and unindexed, but is
often slower than Quick Search.
Figure 8: Network Analyzer log search
Date Select to search logs from a time frame, or select Specify and define a
custom time frame by selecting the From and To date and times.
From Enter the date and select the time of the beginning of
the custom time range.
This option appears only when Date is Specify.
To Enter the date and select the time of the end of the
custom time range.
This option appears only when Date is Specify
Keyword(s) Enter search terms which will be matched to yield log message search
results. To specify that results must include all, any, or none of the
keywords, select from Match.
Quick Search Select to perform a Quick Search, whose Keywords cannot contain
special characters and that searches only indexed fields.
Full Search Select to perform a Full Search, whose Keywords may contain special
characters, and searches all log message fields. The time of the search
varies by the complexity of the search query and the amount of log
messages to be searched.