FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
tnesh
Staff & Editor
Staff & Editor
Article Id 282931
Description

 

This article describes how to transfer/move archived logs from one FortiAnalyzer to another via Log Fetch.

 

Scope

 

FortiAnalyzer.

 

Solution

 

Things to take note of:

  • Both FortiAnalyzers must be running on the same firmware version.
  • The FortiAnalyzer log-fetch role is as follows:
    Client: FortiAnalyzer that fetches/receives log.
    Server: FortiAnalyzer that sends log.

 

Configuration Steps:

In this article:

  • FortiAnalyzer v7.4.1 is used as an example.
  • Log-fetch role and Hostname for both FortiAnalyzers are as follows:
    Client: FAZ-A-Client (receive logs).
    Server: FAZ-B-Server (send logs).

 

  1. Navigate to FAZ-A-Client -> System Settings -> Advanced -> Log Fetch -> Profiles -> Create New.
    For v7.2: the Log Fetch profile can be found under System Settings -> Fetcher Management.

     

  2. Enter the required details -> select OK.

Name

<Log Fetch profile name>

Server IP

<FAZ-B-Server IP address>

User

<FAZ-B-Server username>

Password

<FAZ-B-Server user credential>

 

create-new-profile.png

 

  1. Once done, select the profile -> select Request Fetch.

 

request-fetct.png

 

 

  1. Proceed to enter all the details -> select Request Fetch.

 

request-fetct-details.png

 

  1. Next, navigate to FAZ-B-Server -> System Settings -> Advanced -> Log Fetch -> Sessions -> Create New.
    For v7.2: the Log Fetch profile can be found under System Settings > Fetcher Management.

 

faz-b-receive-request.png

 

     6. Select Review -> review the request details -> proceed to Approve/Reject.

 

faz-b-review-request.png

 

 

  1. Once approved, FAZ-B-Server will display the progress bar under Received Request -> Status.

 

faz-b-after-approve.png

 

  1. Once the transfer is completed, FAZ-A-Client will show Done under Fetch Request -> Status.

 

faz-a-fetch-request-done.png

 

  1. To verify the logs, select the correct ADOM and navigate to FAZ-A-Client -> Log View -> Log Browse.
    Note: Ensure the device is added in FAZ-A-Client under the device manager, otherwise the archived log file will not be visible.

 

after-fetch-verify.png

 

Related articles:

Technical Tip: Debug For Log-Fetch

Technical Tip: How to migrate a FortiAnalyzer logs and config to a new system after RMA or a FortiAn...

Troubleshooting Tip: Log-Fetch Generic error