Fortinet FortiGate Capture Guide For Unified aiFObserve
Best Capture Source
Use FortiGate forward traffic logs with policy logging enabled. Add Application Control and SSL inspection where your policy allows it, because they improve AI application identification.
Basic Logging
- Set
Log Allowed TraffictoAll Sessions. - Prefer session-ending records for lower volume when you only need completed session analytics.
- Use per-session start and end logging when you need early detection or troubleshooting detail.
- Forward logs to FortiAnalyzer, FortiGate Cloud, or syslog.
Minimum fields to export:
- eventtime
- duration
- sessionid
- srcip, dstip
- srcport, dstport
- proto
- sentbyte, rcvdbyte
- sentpkt, rcvdpkt
- action
- policyid, policyname
- srcuser
- app, appcat
Extended Logging
- appid
- applist
- apprisk
- saasname
- hostname, url, domain
- vd, devid, devname
- srcintf, dstintf
- srcgeo, dstgeo
- utmaction, crscore, craction
- web filter, IPS, DLP, and application-control event fields tied to the session
User And App Identity
- srcuser
- FSSO, LDAP, SAML, or FortiAuthenticator-derived user fields
- app, appid, appcat, applist, saasname
- hostname, domain, url
Set Application Control actions to Monitor for visibility-only AI app tracking. Allow may pass traffic without generating the application-control detail required for strong app identity.
AI Provider And Location Evidence
Keep dstip, dstgeo, host/domain/URL, and SaaS/application fields. Region evidence is stronger when cloud and SaaS hostnames are preserved.
Practical Policy Pattern
Create a dedicated outbound policy for AI and SaaS destinations, set allowed traffic logging to All Sessions, attach Application Control in monitor mode, and attach SSL/SSH inspection where appropriate.
Sources
- FortiOS Log Message Reference – Log Message Fields
- FortiOS Traffic Allow Logs
- FortiOS Traffic End Forward Logs
- Fortinet Administration Guide – Application Control