FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
smkml
Staff
Staff
Article Id 300444
Description

 

This article describes how to re-join the cluster device correctly after it is added when HA member auto grouping is disabled.

 

FGT HA.png

 

auto-grouping disable.png

 

By design, if an HA cluster device is added to FortiAnalyzer it will only need to authorize the Primary, but since the ha-member-auto-grouping is disabled the device acts as individually. 

 

It is possible to confirm after authorization it will counted per device, by the command 'diagnose dvm device list'.

 

individual device.png

 

Scope

 

FortiAnalyzer, FortiGate.

 

Solution

 

There are two ways to add the cluster in the FortiAnalyzer device manager:

 

  1. Select the Primary device to edit and add the Secondary Serial Number.

 

add ha in dvm faz.png

 

The HA Status will show Secondary as a New Device instead of the hostname. 

 

add ha in dvm faz2.png

  1. Select the Secondary device and remove the HA Cluster status:

 

add ha in dvm faz3.png

 

Select the Primary device and add HA Cluster List -> Enable From Existing Devices -> Dropdown will show the Secondary device.

 

add ha in dvm faz4.png

 

Note:

Refresh the browser whenever changes are made. It is possible to see the cluster with the correct hostname, and it is detected as one device.

 

add ha in dvm faz5.png

 

add ha in dvm faz6.png

 

Related articles:

Technical Tip: Auto FortiGate HA grouping (based on group name) on FortiAnalyzer 
Technical Tip: Criteria for FortiGate HA member to be auto grouping