FortiGate's web filter writes a key=value line for every site your users touch. In regulated environments, those lines are the difference between "we think staff use chatbots" and a dated inventory you can hand an auditor.
FortiGate is everywhere in hospitals, clinics and regional banks. Which means the evidence for the AI question those boards are now asking already exists on site.
When a nurse pastes a discharge summary into a consumer chatbot, that is PHI at a vendor with unknown terms. The severity does not scale with intent, only with the tool's terms.
Insurers, regulators and accreditation bodies now ask for AI usage inventories in writing. "We ran a dated log audit" is an answer; "we sent a survey" is not.
No procurement, no agents on clinical workstations, no change windows. One log export from the FortiGate you already run, uploaded once.
The healthcare-specific compliance angle, PHI in prompts and triage by training flags, is covered in depth on the HIPAA page. This guide stays on the mechanics.
FortiGate logs are key=value pairs, parsed natively by the audit. Four keys do the work; the rest ride along.
Three-site hospital group, 2,400 staff, FortiGates at each site with FSSO on staff segments. Sample data, presented the way their own incident review ran.
Compliance requested a 30-day AI inventory after an insurer's questionnaire. IT exported web-filter syslog from all three FortiGates, concatenated: 610,000 lines, one full-report upload.
No agents touched clinical devices, which is why the review took days and not a quarter.
31 AI tools. Text and transcription dominate: two consumer chatbots with 214 combined users, one meeting transcriber with 41, one "medical scribe" AI trialing in a single department without procurement.
Register verdicts: both chatbots train unless opted out, the scribe's terms say nothing about training at all. Our wider analysis finds 85.5% of AI tools silent on training, and the scribe fit the pattern.
FSSO identities put names on the clinical-segment usage. The point was never discipline: it was discovering that an entire ward had normalized dictating notes into a consumer app.
Empty-user lines from shared kiosks appeared as source IPs, still countable, still assignable to a ward.
The scribe trial got a proper DPIA and an enterprise contract with no-training terms. The consumer chatbots went to blocked with a sanctioned alternative announced the same day.
The audit PDF, with its dated verdicts, went into the insurer response verbatim. Re-audit scheduled quarterly.
FortiGate attribution quality tracks your authentication setup. All three states produce a valid audit.
Domain identities on every line. The per-user table names people, and coaching or migration lists write themselves.
Identities exist but may be transient. Expect the same person under a couple of session names across a long window.
user= is empty, srcip= stands in. You learn which stations and segments reach AI tools, which in a hospital is often the more important fact.
| Report section | With FortiGate web-filter logs |
|---|---|
| Summary tiles | Complete totals: tools, high-risk, training exposure, abusive-purpose, unsanctioned. |
| Tool table | Every matched hostname with category, risk, sovereignty and the dated training verdict. |
| Per-user table | FSSO and portal identities where present, srcip sources elsewhere, side by side. |
| Blocked vs allowed | action= preserved, so enforcement evidence and demand both stay visible. |
| Sanctioned split | Your approved tools against the observed list, the compliance number in one row. |
| CSV + PDF | Machine-readable table plus the evidence pack, written to be filed as-is. |
The export is read once and discarded. Paths in url= fields are never matched or shown. Reports live 90 days in the account and can be deleted earlier, which your privacy office will ask about.
The sample evidence pack shows the document a FortiGate export produces: tiles, dated verdicts, the per-source breakdown. Sample data, no signup.
Block-verdict domains from the report CSV go into a static URL filter or a custom category on the relevant policies. Abusive-purpose tools first, consumer chatbots per your decision.
Control-verdict tools with real user counts become enterprise-tier procurements with no-training terms, then entries on your approved list for the next run's sanctioned split.
Same window, all sites. Blocked tools should show action=blocked only; the delta slide writes the compliance narrative. Plans with monthly audits are on the pricing page.
Inventory first, then sanction, then block the remainder: the ordering argument is on detect before you block, and it matters double in hospitals where blunt blocking breaks legitimate clinical tools.
Web-filter (utm/webfilter) logs as raw key=value syslog or CSV. Traffic logs work when they carry hostnames, but web-filter lines are the natural unit.
No. Any path to the log lines works: FortiAnalyzer export, syslog collector slice or console download. The line format is what matters.
Those lines attribute to source IPs and segments instead. The tool inventory is unaffected; only name-level attribution narrows.
The audit reads hostnames, identities and timestamps. URL paths are discarded at parse time, the file is deleted after the run, and reports are deletable before their 90-day expiry.
Yes, concatenate the syslog slices. One report per site also works if you want per-site trend lines; both fit inside the same caps.
Coverage lags and granularity is coarse, as the catdesc= examples show. The audit adds dated training verdicts and the sanctioned split that category blocking cannot express.
The hospital group's insurer questionnaire mapped to report sections almost one to one. The common rows:
The tool table, exported as CSV. Dated, sourced from logs, and complete rather than remembered.
Training verdicts plus sovereignty flags per tool triage the list into review order for the privacy office.
"Quarterly log-based audit against a daily-maintained register" plus two PDF dates. That sentence closes the row.
The blocked-vs-allowed evidence and the sanctioned split show both the enforcement and its adoption.
Web-filter volume tracks browsing, not total traffic, so files stay manageable longer than people expect.
A month of web-filter lines usually sits in the tens of thousands. A filtered week can fit the free preview's 5,000 lines.
The scenario's 610,000 lines across three sites fit one full report comfortably. Keep only webfilter subtype lines to stay lean.
Over 2,000,000 lines or 25 MB, shorten the window, split per site, or ask us to take the whole file as a custom run.
Export thirty days of web-filter logs and read the free totals today. The hospital group's insurer answer started exactly there.
Run the free audit