FortiAIOps
Artificial Intelligence and Machine Learning Enhance Network Operations
gvenkatesan
Staff
Staff
Article Id 387218
Description This article describes the required configurations on both the FortiGate Firewall and FortiAIOps to ensure that application data is displayed correctly in FortiAIOps.
Scope FortiOS (all versions) and FortiAIOps (all versions).
Solution

FortiAIOps keeps collecting data from the FortiGate via the REST API and the Syslog protocols. 

 

To integrate the FortiGate Firewall with FortiAIOps, refer to the user guide: Adding and Managing FortiGates.

 

The Applications page provides information about the applications used by clients on the wireless network. This page consists of three widgets: Apps by usage, Apps by risk, and Users by usage.

 

This page can be accessed under Wireless -> Applications

 

If the application dashboard does not show any details, as shown below, check the following configurations on the FortiGate firewall. 

 

applications dashboard on ForrtiAIOps.png

 

FortiGate config checks: 

 

  1. Check if the FortiGate Firewall is reporting the applications usage: 
  • The application usage can be seen under the 'FortiView Applications by Bytes' options present under the FortiGate Dashboard options. 
  •  For the FortiGate to detect applications, the following conditions are necessary: 
    • The 'Application Control default' profile must be enabled on the Firewall policy.
    • Make sure that the FortiGate unit contains a valid FortiGuard subscription and can reach the FortiGuard server. 
  • Once these conditions are satisfied, the application category will be visible on the 'FortiView Applications by Bytes' Dashboard.

 

FortiView Applications by Bytes.png

 

  1. Make sure that the FortiAIOps is added as the syslog server on the FortiGate Firewall: 

  • To add the ForiAIOps as the syslog server, browse to Log & Report -> Log Settings -> Global Settings
  • Enable 'syslog logging' option and provide the FortiAIOps management IP address. 

 

Once both these settings are done, the FortiAIOps will start populating the application details as expected. 

 

Applications_FortiAIOPS_1.png