Troubleshooting Tip: Intrusion Prevention logs showing 'no data found' for Attack Name column information
Description
This article describes a situation where the user is unable to view IPS signature details in the Log View-Security: Intrusion Prevention section of FortiAnalyzer. The user clicks on any IPS signature link under the Attack Name column, but a popup shows no data found.

 
Scope
FortiAnalyzer.
Solution
To resolve this issue, ensure that the FortiAnalyzer has the IOC (Indicators of Compromise) license. This license is required to view attack information on the IPS logs.
Verify that the IOC license is installed and activated on the FortiAnalyzer. The independent SKU license should be in the format FCx-10-xxxxx-661-0x-DD.

 
To check the information from the CLI, run the following command:
FAZ-76 # diagnose test application sqllogd 204 stats
License of post breach detection installed.
License expiration_str: 2026-11-29
TIDB version : 00000.03545-2602260436
TIDB load time : 2026-02-26 13:29:14
infected-ip : 97365, add 487253, del 0, realloc 50810, merge 0, mem(init/curr) 264/2606680, bucket 50810/65536, avg_bkt_load 1
infected-domain : 1737431, add 8491246, del 0, realloc 262217, merge 803, mem(init/curr) 264/31993464, bucket 261785/262144, avg_bkt_load 6
infected-url : 1137644, add 4250153, del 0, realloc 53705, merge 61, mem(init/curr) 264/18726856, bucket 32768/32768, avg_bkt_load 34
suspicious-url : 1, add 5, del 0, realloc 1, merge 0, mem(init/curr) 264/524576, bucket 1/32768, avg_bkt_load 1
count of wlog(threat/total) 0/0.
count of tlog(threat/total) 0/3.
count of olog(threat/total) 0/0.
count of slog(threat/total) 0/0.
count of alog(threat/total) 0/0.
count of elog(threat/total) 0/2.
count of cs wlog(distinct/checked) 0/0.
last bloom filter clr: 2026-02-27 00:00:00
FAZ-76 #

