FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
Nur
Staff
Staff
Article Id 241875
Description This article describes when the log transfer between an old and a new FortiAnalyzer fails (cloud or VM/on-prem).
Scope

FortiAnalyzer (firmware 6.4.8).

Solution

There are two ways to import / export the log:

 

1) From GUI:

Go to Log Browse -> Download || Log browse -> Import.

 

2 From CLI:

FTP / SFTP / SCP Server ( The user needs to install the server to local workstation).

 

Hence, this article is related with transfer log from GUI.

 

While the log is imported to the Fortianalyzer, it is possible to receive an error as below :

'backend service failed'.

 

Nur_1-1672802970887.png

 

To fix this issue:

1) FortiGate needs to be integrated with FortiAnalyzer.

2) Select 'Import' from log browse.

3) Device: (choose the FortiGate Serial Number).

4) add the log from local workstation.

5) Select 'Ok'.

 

Related article:

Technical Tip: Backup and restore of FortiAnalyzer settings, logs and reports