FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
tnesh
Staff
Staff
Article Id 241301
Description This article describes how to view and edit the FortiManager/FortiAnalyzer system configuration file (system.conf).
Scope FortiManager/FortiAnalyzer.
Solution

These steps require 7-zip, WinRar, or any similar archive-opening application to open the backup config file (.dat). This article will use 7-Zip as an example.

 

  1. Download the FortiManager/FortiAnalyzer backup config.

  2. 'Right-click' the file, select Open with, and choose 7-Zip File Manager.

 

tnesh_0-1672246874708.png

 

  1. Select the file:

     

    tnesh_1-1672245935943.png

     

     

  2. Select var -> fwclienttemp -> system.conf.

     

    tnesh_0-1672302850059.png

     

     

  3. Open and edit system.conf by 'right-clicking' it and selecting Edit.

    tnesh_2-1672246037376.png

     

     

  4. The system.conf file will be opened in the default Notepad application. For example, it is possible to edit or remove the shell access password.

     

  5. View / Edit the content, then save the file and exit (in any case check if the CLI that you will add is correct and copy paste from a live SSH session if needs be).

    1. Optionally, change the admin password and/or admin username.

    2. Optionally, remove the shell password.

  6. When prompted, select 'OK' to update the archive file:

     

    tnesh_1-1672244687985.png

     

  7. Select 'OK' again to update the parent archive file:

     

    tnesh_3-1672244838569.png

     

  8. Make sure to update both archive files.

     

  9. Open system.conf again and verify that the changes are reflected.

     

  10. Proceed to restore using the updated backup config file in FortiManager/FortiAnalyzer.

     

Related article:

Technical Tip: How to change the Admin default User.