Skip to main content
HernandezA
Staff
Staff
March 19, 2026

Troubleshooting Tip: FortiAnalyzer does not show logs for some categories

  • March 19, 2026
  • 0 replies
  • 329 views
Description This article describes how to discard issues in FortiAnalyzer when some categories do not appear in log view.
Scope FortiAnalyzer.
Solution

In this example, FortiAnalyzer does not show Antivirus logs or Intrusion Prevention event logs.

 

not antivirus nor IPS log events.jpg

 

  1. Confirm the FortiGate and FortiAnalyzer connectivity.


device up confirmation.jpg

 

FGT Fabric connector up.jpg

 

log1.jpg

 

If the connectivity status does not show up, check this article: Troubleshooting Tip: FortiGate to FortiAnalyzer connectivity 

 

  1. Confirm in FortiGate that configuration profiles have been created and assigned to firewall policies (Antivirus profile and Intrusion Prevention). If they have not, create them and assign them to a firewall policy (the default can be used for test purposes).

 

In FortiGate Security Profiles -> Antivirus or Security Profiles -> Intrusion Prevention -> Default Profiles -> Antivirus or Security Profiles -> Antivirus -> Default.

 

default_antivirus.jpg

 

defaultIPS.jpg

 

  1. Confirm the profiles were assigned to a firewall policy that records sessions and logs.

assignprofile to a policy.jpg
  1. Confirm events are recorded (in FortiGate Log & report -> Security Events -> Logs -> Intrusion Prevention or Log & report -> Security Events -> Logs -> AntiVirus). First, use the memory option to confirm events exist in the FortiGate that match the rules.

verify security events AV.jpg

 

verify security events IPS_mem.jpg

 

  1. At this point, if no data is displayed, it likely means no related events have been identified. It is therefore normal that FortiAnalyzer does not show any logs. To generate test logs from FortiGate and confirm if the FortiAnalyzer receives them, execute 'diagnose log test' in FortiGate.

diag_log test.jpg

 

  1. The logs should appear in FortiGate and FortiAnalyzer after a few minutes. Confirm the events/logs in FortiGate by checking Log & Report -> Security Events -> Logs -> AntiVirus/Intrusion Prevention.


afterLog_test_FAZ.jpg


afterLog_test_mem.jpg after_log_test_AV_mem.jpg


after_log_test_AV_FAZ.jpg

 

  1. After, the logs will be displayed in FortiAnalyzer.


afterlog test in FAZ menus events are displayed.jpg

 

In summary, the issue may be caused by unaddressed problems on the FortiAnalyzer side, and the root cause can be uncovered by testing log generation and reception processes between FortiGate and FortiAnalyzer.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!