Skip to main content
spoojary
Staff
Staff
September 28, 2023

Troubleshooting Tip: Report Generation Issues on FortiAnalyzer

  • September 28, 2023
  • 0 replies
  • 5124 views

Description

This article describes troubleshooting steps for FortiAnalyzer report generation issues where reports remain in Pending or Running state, or report generation does not complete as expected. The examples apply to FortiAnalyzer v7.2.3 and later; however, command availability and behavior should always be verified against the CLI Reference for the specific firmware version.

Scope

FortiAnalyzer.

Solution

Challenge: Experienced difficulty in generating reports on FortiAnalyzer. The platform showed numerous reports in a pending state.

 

Actions Taken:

  1. The issue was reproduced for a detailed understanding.

  2. Logs and error evidence were collected for analysis.

  3. Multiple commands were executed to diagnose the issue:

    • The current status of pending reports was checked: 'diagnose report status pending', and running reports were checked with the commands: 'diagnose report status running'.

    • Attempted to reset task history with: 'diagnose dvm task reset' ---> This will trigger a reboot, so ensure to take a maintenance window and backup the system.

      However, this command did not resolve the pending reports issue, even after a reboot.

    • The report queue was cleared using the 'diagnose report clean report-queue'. 

    • Several processes were restarted to attempt to resolve the issue, including the sqlreportd daemon:

 

diagnose test application sqlreportd 99
diagnose test application sqlplugind 99
diagnose test application sqllogd 99

 

Post-actions, the pending reports were verified to be cleared. Able to successfully generate reports afterward.

 

Additionally, refer to Technical Tip: When a manual rebuild of hcache tables is advisable for further troubleshooting related report issues, on how and when to trigger a manual rebuild of hcache tables.

The FortiAnalyzer issue of generating reports was addressed by clearing the report queue and restarting specific processes. Should such an issue arise, it is advised to follow the steps mentioned above. For any further assistance, it is possible to contact the Fortinet Support Center.

Caution:

diagnose dvm task reset should not be used as a routine first-line action for report generation issues.


This command resets the task database to its factory default state, erases existing tasks and task history, and reboots the FortiAnalyzer. Use it only when there is clear evidence of a corrupted or stuck task database, preferably under TAC guidance, and only after confirming a valid backup and an approved maintenance window.


In the example case, diagnose dvm task reset did not resolve the pending report issue. The issue was resolved after clearing the SQL report queue and restarting the report/SQL-related daemons.

 

Related article:

Troubleshooting Tip: Empty reports

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!