FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
lingky88
Staff
Staff
Article Id 320184
Description This article describes how to troubleshoot issues related to CIS Controls Security Rating Report Generation Failure on FortiAnalyzer.
Scope FortiAnalyzer v7.4 onwards.
Solution
  1. Ensure that the FortiAnalyzer and FortiGate are on v7.4 and above. Check if the Security Rating licenses are present on both devices.

On FortiAnalyzer:

 

1. FAZ license.png

 

On FortiGate:

 

2. FGT license.png

 

  1. Ensure the FortiGate is registered to FortiAnalyzer and the logging status is UP.

 

3. FortiGate status up.png

 

  1. Run the Security Rating Report on the FortiGate and check the Security Rating summary log on the FortiAnalyzer. Run the following debugs while performing this step to verify the RESTAPI response.

 

On FortiAnalyzer:

 

diag debug reset

diag debug disable

diag test application oftpd 95 enable "RESTAPI REQUEST" "RESTAPI RESPONSE"

diag debug timestamp enable

diag debug enable

 

On FortiGate:

 

diag debug reset

diag debug disable

diag debug application httpsd -1

diag debug console timestamp enable

diag debug enable


4. Security Rating log in FortiAnalyzer.png

 

  1. Enable the backend-shell access on the FortiAnalyzer. See also the KB article Technical Tip: How to enable backend-shell access in FortiManager/FortiAnalyzer.

 

FAZ # config system admin setting

(setting)# set shell-access enable
Enter new password:
Confirm new password:

(setting)# end

 

  1. Enter the shell and check if the PostureReport files for the FortiGate are present under the drive0/private/restapi/audit_rpt/ directory.

 

5. Shell.png

 

  1. Proceed to generate the report under Reports -> Report Definitions -> CIS Controls Security Rating Report -> Run Report.

 

6. Run CIS Controls Security Rating Report.png

 

  1. Check if there are any crash logs present when running the report:

 

FAZ # diag debug crashlog read