Skip to main content
Nur
Staff
Staff
July 17, 2023

Technical Tip: How to make multitenancy visible from FortiAnalyzer

  • July 17, 2023
  • 0 replies
  • 903 views
Description This article describes how to make multitenancy visible from FortiAnalyzer.
Scope FortiAnalyzer and EMS.
Solution

By default, Multitenancy is disabled from EMS. However, when EMS has been integrated with FortiAnalyzer, the multitenancy is visible only for global and root.

 

To ensure the other multitenancy is visible from FortiAnalyzer, follow the steps below:

 

  1. Enable from EMS:

Go to System setting -> Manage multiple sites -> Save.

 

Capture.JPG

 

 

  1. The multitenancy will appear from the top of the EMS bar.
  2. To create a multitenancy, go to Global -> Configure Sites -> Add.
 
Capture.JPG

 

 

  1. After adding the multitenancy, enable the logging section ( the attachment showed multitenancy 'Nur1 ') by going to Endpoint Profile -> System Settings -> Log, upload the log to FortiAnalyzer/FortiManager -> Enable, add FortiAnalyzer/FortiManager IP, enable SSL and save.
 
Capture.JPG

 

 

  1. Assign endpoint to the multitenancy
  • The endpoint assignment to multitenancy needs to be performed from endpoint
  • Go to FortiClient, disconnect from EMS Server, and add the EMS Server IP -> Site Name ( in this case 'Nur1 ').

From FortiClient:

 

Nur_3-1689571947331.jpeg

 

From EMS:

 

Capture.JPG

 

When Multitenancy has been enabled and the endpoint been added to multitenancy, the FortiAnalyzer will appear as below:

 

Capture.JPG

 

From the log view, it is possible to see the traffic of the endpoint and the VDOM they located:

 

Capture.JPG

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.