Skip to main content
mateusguilherme
Explorer II
May 27, 2025
Solved

Fortianalyzer does not display logs

  • May 27, 2025
  • 3 replies
  • 2326 views

Hello! Our fortianalyzer stopped displaying logs 2 days ago. I am using fortigate with version 7.0.13 build0566 and fortianalyzer with version 7.6.3.
From the fortigate graphical interface I can successfully run a connection test with fortianalyzer. However, through the CLI command "execute log fortianalyzer test-connectivity" I see the output "Log: Tx & Rx (log not received)":

 

execute log fortianalyzer test-connectivity FortiAnalyzer Host Name: FAZ-MINUANO FortiAnalyzer Adom Name:  FortiGate Device ID: FGT40FTK21099EV4 Registration: registered Connection: allow Adom Disk Space (Used/Allocated): 0B/Unlimited Analytics Usage (Used/Allocated): 0B/Unlimited Analytics Usage (Data Policy Days Actual/Configured): 0/0 Days Archive Usage (Used/Allocated): 0B/Unlimited Archive Usage (Data Policy Days Actual/Configured): 0/0 Days Log: Tx & Rx (log not received) IPS Packet Log: Tx & Rx Content Archive: Tx & Rx Quarantine: Tx & Rx  Certificate of Fortianalyzer valid and serial number is:FAZ-XXXXXXX


Below is an image of how the LOG session of our fortianalyzer appears. It seems that some menu buttons have disappeared.

faz.png

I have already run the "diag sys fsck harddisk" command in fortianalyzer and no disk problems were found.

When I run the "diagnose sql status" command in fortianalyser, nothing is displayed.

Does anyone have any tips?

Best answer by mateusguilherme

the command "exec sql-local rebuild-db" solved the problem

3 replies

funkylicious
SuperUser
SuperUser
May 28, 2025
mateusguilherme
Explorer II
May 28, 2025

And I ran the command "exec sql-local rebuild-db" and the result of the command "execute log fortianalyzer test-connectivity" changed and now the information of received logs appeared again "Log: Tx & Rx (290 logs received since 07:46:16 05/28/25)". However this process will take a long time (approximately 20h to complete). I will update this post when it is finished.

mateusguilherme
mateusguilhermeAuthorAnswer
Explorer II
May 28, 2025

the command "exec sql-local rebuild-db" solved the problem