FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
jasonhong
Staff
Staff
Article Id 262447
Description

This article describes how the FortiAnalyzer Chart Builder function works and explains why in some circumstances Chart Builder preview will return no data.

Scope

FortiAnalyzer.

Solution
  1.  In some circumstances, the user might see 'No Data' in the preview when using the Chart Builder function in Log View even if there are data shown when applying the same set of filters in Log View.

 

previewnodata.png

 

     2. If the same query is copied and applied when creating a sample Dataset under Reports, the user is able       to see results being generated when running the same query.

 

dataset.png

 

     3. The above conflicting scenarios can be explained as follows:

  • Chart Builder (Log View): SQL query and filters are only matched against the first few pages/sections of Log View/Analytics Logs.
  • Dataset Query (Reports): SQL query and filters are matched against all pages/sections of Log View/Analytics Logs.

There is a limitation set on the Chart Builder function in FortiAnalyzer to only match the SQL query and filters against the first few pages/sections of Log View/Analytics Logs. This limitation is applied in Chart Builder to avoid FortiAnalyzer DB running into out-of-memory issues.

Contributors