FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
Nur
Staff
Staff
Article Id 264308
Description This article describes how to make multitenancy visible from FortiAnalyzer.
Scope FortiAnalyzer and EMS.
Solution

By default, Multitenancy is disabled from EMS. However, when EMS has been integrated with FortiAnalyzer, the multitenancy is visible only for global and root.

 

To ensure the other multitenancy is visible from FortiAnalyzer, follow the steps below:

 

  1. Enable from EMS:

Go to System setting -> Manage multiple sites -> Save.

 

Capture.JPG

 

 

  1. The multitenancy will appear from the top of the EMS bar.
  2. To create a multitenancy, go to Global -> Configure Sites -> Add.
 
Capture.JPG

 

 

  1. After adding the multitenancy, enable the logging section ( the attachment showed multitenancy 'Nur1 ') by going to Endpoint Profile -> System Settings -> Log, upload the log to FortiAnalyzer/FortiManager -> Enable, add FortiAnalyzer/FortiManager IP, enable SSL and save.
 
Capture.JPG

 

 

  1. Assign endpoint to the multitenancy
  • The endpoint assignment to multitenancy needs to be performed from endpoint
  • Go to FortiClient, disconnect from EMS Server, and add the EMS Server IP -> Site Name ( in this case 'Nur1 ').

From FortiClient:

 

Nur_3-1689571947331.jpeg

 

From EMS:

 

Capture.JPG

 

When Multitenancy has been enabled and the endpoint been added to multitenancy, the FortiAnalyzer will appear as below:

 

Capture.JPG

 

From the log view, it is possible to see the traffic of the endpoint and the VDOM they located:

 

Capture.JPG