FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
pragyasharma
Staff
Staff
Article Id 393787
Description This guide outlines the steps required to migrate from a physical FortiAnalyzer-400E device to a virtual FortiAnalyzer VM64 (FAZVM64). It includes backup, configuration editing, VM deployment, and restoration steps.
Scope Applies to users who want to move from FortiAnalyzer-400E (hardware) to a FortiAnalyzer VM64 on VMware.
Solution

 

  1. Backup the FortiAnalyzer-400E Device.

 

Create a full backup of the hardware FortiAnalyzer device using the following guides:

 

  1. Modify the Backup File.

 

Use 7-Zip or another archive tool to open the backup file and navigate to the following path:

 

FAZ_Backup.dat\FAZ_Backup\var\fwclienttemp\system.conf
  • Open system.conf.
  • Replace all instances of FAZ_400E with FAZ_VM64.
  • Save the file back into the archive.

For additional guidance, refer to Technical Tip: How to Migrate FortiAnalyzer Log and Config to Another Unit.

 

  1. Deploy the FortiAnalyzer VM64 on VMware.

 

Follow Fortinet’s instructions to install FortiAnalyzer 7.4.X on VMware:

 

  1. Restore Configuration to the New VM.

 

Once the VM is ready:

  • Restore the modified backup file

    • Important: Uncheck the option to overwrite current IP and routing settings during the restore.

See Restoring the Configuration – Fortinet Documentation.

 

Note: In 7.4.3 onwards, the migration option is available in the GUI. For more information, follow the Fortinet documentation instructions for migrating the configuration:

Migrating the configuration - FortiAnalyzer 7.4.3 administration guide.

 

2025-06-25_17h38_24.png