Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
danielgoal
New Contributor

difference between the values appear in report output on FA and policy count on FG

I want to monitor bandwidth used by Fortigate policies with Fortianalyzer but there is difference between the values appear in report output (bandwidth policy:Top 30 Policies by Bandwidth) on Fortianalyzer and policy count(byte in 5.4) on Fortigate. (I. e. the policy count is 58.55MB and the Fortianalyzer report shows 55.84MB for bandwidth policy) I'm confused which one is right. What does the difference mean? How can I get the correct result?

 

2 Solutions
AtiT
Valued Contributor

Hi,

there is a possibility that there was an ongoing session via policy 2 when the report was generated that caused the difference.

AtiT

View solution in original post

AtiT
hzhao_FTNT

Hi there, local traffic/invalid sesssions/duplicate sessions will be excluded from FAZ report.

 

hz

View solution in original post

6 REPLIES 6
danielgoal
New Contributor

Is that a bug ?Submit Post

AtiT
Valued Contributor

Hi,

there is a possibility that there was an ongoing session via policy 2 when the report was generated that caused the difference.

AtiT

AtiT
hzhao_FTNT

Hi there, local traffic/invalid sesssions/duplicate sessions will be excluded from FAZ report.

 

hz

danielgoal

hi hz,

thanks a lot

your reply is so helpful

i guess the issue is related to what you mentioned.

would you please explain a little more about "Invalid Sessions/Duplicate Sessions" ?

Is there any fortinet document available for this issue?

 

P.S. Which value should be considered as real traffic throughput in a policy?

hzhao_FTNT

Logid filter "logid_to_int(logid) not in (4, 7, 14)" is applied to all traffic-log related datasets. This filter will exclude:

4: "Other start" sessions which is double counted before; 7: invalid sessions 14: local traffic

danielgoal

Hi AtiT, Thank you for your reply i had cleared all sessions before i ran reports,so i think there wasn't any running sessions on the device.

Labels
Top Kudoed Authors