Skip to main content
Staff
July 10, 2026

Troubleshooting Tip: FortiGate HA not showing logs from FortiAnalyzer

  • July 10, 2026
  • 0 replies
  • 455 views

Description

This article describes the issue when FortiAnalyzer logs fail to load on FortiGate HA cluster after upgrading FortiAnalyzer to v7.4.11.

Scope

FortiGate HA running v7.4.9, v7.4.11, v7.4.12.

FortiAnalyzer v7.4.11.

Solution

Matching criteria:

  • FortiGate are in HA pair. Standalone FortiGates are not affected.

  • FortiAnalyzer running v7.4.11.

  • Logs appearing in FortiAnalyzer. The output of 'execute log fortianalyzer-cloud test-connectivity' from the FortiGate shows real time or recent Log: Tx & Rx. 

  • When navigating to FortiGate Log & Report > Forward Traffic Logs > Set source as FortiAnalyzer, no logs are displayed. Selecting 'Memory' or 'Disk' (if available) displays logs.

FGT # execute log fortianalyzer-cloud test-connectivity
Testing connectivity to fortianalyzer-cloud ...
FortiAnalyzer Host Name: FAZ-FTNT-CLOUD
FortiAnalyzer Adom Name: root
FortiGate Device ID: FG101FTKxxxxxxxx
Registration: registered
Connection: allow
Adom Disk Space (Used/Allocated): 1184120B/80530636800B
Analytics Usage (Used/Allocated): 1016184B/32212254720B
Analytics Usage (Data Policy Days Actual/Configured): 0/100 Days
Archive Usage (Used/Allocated): 167936B/48318382080B
Archive Usage (Data Policy Days Actual/Configured): 0/365 Days
Log: Tx & Rx (4 logs received since 14:09:24 07/29/25)
IPS Packet Log: Tx & Rx
Content Archive: Tx & Rx
Quarantine: Tx & Rx


  • Displaying FortiAnalyzer on CLI also displays no output.

FGT# execute log filter device 3
FGT# execute log filter category event
FGT# execute log display


  • A similar output is seen on FortiAnalyzer when running the command, 'diagnose debug app fazsvcd 8':

diagnose debug app fazsvcd 8
[T3793:utils.c:2372] is_all_vdom_included 2372 can't get vdom list for devid[DEVICE_NAME] cluser_id[53971XXXX] under adom[root]


Workaround:

Display logs on FortiAnalyzer, or in FortiGate from disk (if available) or memory (if memory logging is enabled). To enable logging to memory, refer to Technical Tip: How to configure logging to memory in FortiOS.


Resolution:

The issue is caused by the LogView API requiring all HA members to be included as device IDs (devids) when the caller device belongs to an HA cluster in OFTPD.

The fix is included in FortiAnalyzer firmware versions v7.4.12 and v7.6.4.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.