FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
psalian
Staff & Editor
Staff & Editor
Article Id 194478

Description

 
By design on the FortiAnalyzer:
 
  1. It is always expected to see the secondary members with a serial number and not a host name under the device manager as HA is recognized via the HA group name used on the FortiGate Cluster, and is mapped to the primary serial number.
  2. The secondary member will show up as 'New Device' instead of a device name or Serial number when using the option 'Add Other Device' -> new serial number, followed by the '+' button.
 
This article explains how to bypass this limitation to rename secondary members with a hostname.


Scope

 

v5.6.3 or later and v6.x.


Solution

 
Use the following steps to rename the secondary member:
 
  1. Disable using the HA group name as follows (keeping it enabled would add the cluster with the secondary using its serial number):

 

config sys global
    set set ha-member-auto-grouping disable
end

 

  1. Use the Device Manager to add the FortiGate cluster - primary device to FortiAnalyzer.

 

psalian_FD43675_tn_FD43675-1.jpg
 
  1. Edit the primary. The secondary device details will not be present.

  1. Select 'Add other device' and provide the serial number of the secondary, then select '+'. The secondary will be added as 'New Device'.
 
psalian_FD43675_tn_FD43675-2.jpg
 
Do not use this option.

  1. The secondary device will show up in the 'Unregistered Device' list. Promote it to the FortiAnalyzer. It will be added as a separate device. A name can be given when promoting it.

 

psalian_FD43675_tn_FD43675-3.jpg

 
psalian_FD43675_tn_FD43675-4.jpg
 
  1. Edit the secondary device and uncheck the 'HA Cluster' check box.

 

psalian_FD43675_tn_FD43675-5.jpg

 
  1. Edit the primary FortiGate and select 'Add Existing Device'. The drop-down list will show the secondary device.

 

psalian_FD43675_tn_FD43675-6.jpg

 
  1. The cluster is now added with the proper hostnames.

 

psalian_FD43675_tn_FD43675-7.jpg
 
  1. The name of this cluster can now be changed as required.
 
psalian_FD43675_tn_FD43675-7.jpg
 
Related article: