FortiAnalyzer Fault Reports
Hello guys ,
I have a problem with reports from FortiAnalyzer.
I'm gonna explain my 'topology' the best way i can.
Firstly, there is a standalone EMS that pushes the logs of the hosts to the FortiAnalyzer. I can see the logs in Fortianalyzer , so we are sure that we have them in the right place and there isnt a conneciton problem.
It seems that when i run a report (new or old) it's contents its the same almost every time and there is only one host in its results. I use the default report editor (i have tried use different choices in the graphs but no desired result). Also i give it a try with and without the extended log filtering and checked all the options (device , source ip, dest ip, endpoint id....). Enable High Accuracy Caching also checked in case there is a problem with the number of logs.
FortiAnalyzer uses ADOM (the correct one selected) , version v7.6.3 build3492 (Feature)