Skip to main content
WinterSnowYap
Staff
Staff
March 3, 2026

Technical Tip: FortiAnalyzer expected behavior with FortiGate HA

  • March 3, 2026
  • 0 replies
  • 290 views
Description This article describes what the FortiAnalyzer's expected behavior is with FortiGate HA.
Scope FortiAnalyzer.
Solution

The following is the scenario:

 

There is a FortiGate HA connected to FortiAnalyzer.

 

Before FortiGate HA failover:

FGT_A (Primary role), Serial Number ended with ...24.

FGT_B (Secondary role), Serial Number ended with ...83.

 

202603_FAZ_FGT_HA_001.png

 

After FortiGate HA failover:

FGT_B (Primary role), Serial Number ended with ...83.

FGT_A (Secondary role), Serial Number ended with ...24.

 

202603_FAZ_FGT_HA_002.png

 

At FortiAnalyzer's Device Manager, it does not have FortiGate HA role information. When FortiGate performs any failover action, FortiAnalyzer will only show FortiGate Name and FortiGate Serial Number.

 

202603_FAZ_FGT_HA_003.png

 

Notes:

If both FortiGate (Primary and Secondary) HA can connect to FortiAnalyzer, then FortiAnalyzer will be able to receive logs from both FortiGate (Primary and Secondary) HA.

 

At FortiAnalyzer, go to Device Manager -> Last Log Time status shows (0 minutes ago), it mean FortiAnalyzer continuously receives logs from FortiGate.

 

202603_FAZ_FGT_HA_004.png

 

At FortiAnalyzer, go to Log View -> Logs -> Log Browse -> It is possible to show both FortiGate (Primary and Secondary) HA's Serial Number.

 

202603_FAZ_FGT_HA_005.png

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!