Enter Password



aiFWall Logo aiFObserve

Distributed, Contextual Visibility & Governance for Enterprise AI Traffic. No Agents, No APIs, No

Fortinet FortiGate Capture Guide For Unified aiFObserve

Best Capture Source

Use FortiGate forward traffic logs with policy logging enabled. Add Application Control and SSL inspection where your policy allows it, because they improve AI application identification.

Basic Logging

  1. Set Log Allowed Traffic to All Sessions.
  2. Prefer session-ending records for lower volume when you only need completed session analytics.
  3. Use per-session start and end logging when you need early detection or troubleshooting detail.
  4. Forward logs to FortiAnalyzer, FortiGate Cloud, or syslog.

Minimum fields to export:

Extended Logging

User And App Identity

Set Application Control actions to Monitor for visibility-only AI app tracking. Allow may pass traffic without generating the application-control detail required for strong app identity.

AI Provider And Location Evidence

Keep dstip, dstgeo, host/domain/URL, and SaaS/application fields. Region evidence is stronger when cloud and SaaS hostnames are preserved.

Practical Policy Pattern

Create a dedicated outbound policy for AI and SaaS destinations, set allowed traffic logging to All Sessions, attach Application Control in monitor mode, and attach SSL/SSH inspection where appropriate.

Sources