Skip to main content
markwarner
Staff
Staff
August 17, 2023

Troubleshooting Tip: FortiView Top Source Addresses and Top Destination Addresses show no record found

  • August 17, 2023
  • 0 replies
  • 3191 views

Description

This article describes how to fix a possible cause behind the 'Top Source Addresses' and 'Top Destination Addresses' showing 'no record found' in FortiView, while the other sections do.

no logs.png

 

Scope

All supported versions of FortiAnalyzer and FortiGate.

Solution

These charts rely on the source and destination UUIDs in FortiGate traffic logs.
The option on the FortiGate is disabled by default, as the UUID strings are quite long and will increase the disk usage when enabled.

To enable UUID logging from the FortiGate, go to Log & Report -> Log Settings -> UUIDs in Traffic Log and enable the option.

 

log setting.JPG


The corresponding CLI configuration on FortiGate is as follows:

config system global
    set log-uuid-address enable
end


In FortiOS v6.2.x and v6.4.x, extra configuration should be enabled from the GUI as follows:

UUID.jpg


  • 'set log-uuid-policy enable' is configured regarding policy UUID logs.


config system global
    set log-uuid-address enable
    set log-uuid-policy enable 
end


Related articles:

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.