FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
smkml
Staff
Staff
Article Id 300444
Description

 

This article describe how to re-join the cluster device correctly after it added when HA member auto grouping are disable.

 

FGT HA.png

 

auto-grouping disable.png

 

By design, if an HA cluster device is added to FortiAnalyzer it will only need to authorize the Primary, but since the ha-member-auto-grouping is disabled the device acts as individually. 

 

It is possible to confirm after authorization it will counted per device, by the command 'diagnose dvm device list'.

 

individual device.png

 

Scope

 

FortiAnalyzer, FortiGate.

 

Solution

 

There are two ways to add the cluster in the FortiAnalyzer device manager:

 

  1. Select the Primary device to edit and add the Secondary Serial Number.

 

add ha in dvm faz.png

 

The HA Status will show Secondary as a New Device instead of the hostname. 

 

add ha in dvm faz2.png

  1. Select the Secondary device and remove the HA Cluster status:

 

add ha in dvm faz3.png

 

Select the Primary device and add HA Cluster List -> Enable From Existing Devices -> Dropdown will show the Secondary device.

 

add ha in dvm faz4.png

 

Note:

Refresh browser whenever changes are made. It is possible to see the cluster with the correct hostname, and it is detected as one device.

 

add ha in dvm faz5.png

 

add ha in dvm faz6.png

 

Related article:

Auto FortiGate HA grouping (based on group name) on FortiAnalyzer 

Contributors