FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
Vbharath_FTNT
Article Id 195357

Description

 

This article describes how to upgrade FortiAnalyzer firmware.


Solution

 

Before Upgrade:

  • Fortinet recommends uploading firmware to FortiAnalyzer by using a server that is in the same location as the FortiAnalyzer. This helps avoid timeouts.
  • For the Collector-Analyzer architecture upgrade, Fortinet recommends upgrading the Analyzer first. Upgrading the Collector first might affect the Analyzer’s performance.
  • To upgrade firmware for a cluster, Fortinet recommends upgrading the HA Slaves first, followed by the HA Master last. To avoid losing log information, wait until each FortiAnalyzer upgrade has finished before proceeding to the next.
  • It is important to read the release notes which are as well available from the Fortinet Customer Service & Support site (https://support.fortinet.com/) at the same location from where you downloaded the firmware image. Once downloaded, review the special notices, upgrade information, product integration and support, resolved issues, known issues, and limitations.

 

Release notes can be also found at the below location.

FortiAnalyzer

 

 To upgrade firmware:

  1. Go to System Settings -> Dashboard.
  2. In the System Information widget, go to the Firmware Version field, and select the Upgrade Firmware icon.

                  System_Inf_widget_FAZSystem_Inf_widget_FAZ

 

  1. In the Firmware Upload dialog box, select Browse to locate the firmware package (.out file) downloaded from the Customer Service & Support portal, and select Open.
    It is possible to reference this link to check the process of how to locate the file on the support page.

    How to locate a FortiAnalyzer device imag... - Fortinet Community

     

    File_Size_FAZFile_Size_FAZ

    Upload_Firmware_FAZUpload_Firmware_FAZ                                              

  2. Select OK.
                                           

    Select_FAZ_File_OKSelect_FAZ_File_OK                            

    The firmware image is uploaded. When the upgrade completes, a message confirms a successful upgrade.
                                          

    Loading_ProcessLoading_Process

                                                                                

    It is recommended to view the console log output during the upgrade. See Checking FortiAnalyzer log output.
                                                                            

    Console_update_processConsole_update_process                                                          

     

  3. When the login window displays, log into FortiAnalyzer.

    When the upgrade completes, it will be possible to have to refresh the web browser to see the login window.

     

  4. If the database needs rebuilding, it is possible to monitor the rebuild status by selecting the Rebuilding DB status in the toolbar.
                                              

    JeanPhilippe_P_0-1724826336377.png

                                                        

    The rebuild process includes two steps. When it is done, there will be the Rebuilding log database completed message.

    Note: Some features are unavailable while the SQL database is rebuilding.

    Rebuil_Process_after_UpgradeRebuil_Process_after_Upgrade                                                         

     

  5. Review the System Settings -> Event Log for any additional errors. See Checking FortiAnalyzer events.

     

  6. Optionally, it is possible to upgrade the firmware stored on an FTP or TFTP server using the following CLI command:

    execute restore image {ftp | tftp} <file path to server> <IP of server> <username on server> <password>