FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
smkml
Staff
Staff
Article Id 422829
Description

 

This article describes how to troubleshoot when a default FSBP Security Rating Report populates no data.

 

security posture.png

 

fabric coverage.png

 

optimization.png

 

Scope

 

FortiAnalyzer.

 

Solution

 

  1. Make sure FortiAnalyzer has an additional license with SKU FC1-10-XXXX-175-XX-XX, and after registering, it should display in FortiCloud under Entitlement as FortiGuard Attack Surface Security Service and in FortiAnalyzer GUI as Security Rating Update.

 

FortiCloud shows FortiGuard Attack Surface Security Service.png

 

FAZ license Security Rating Update.png

 

  1. Make sure FortiGate has an additional license with SKU FC-10-XXXX-175-XX-XX, and after registration, it should display in FortiCloud under Entitlement as FortiGuard Attack Surface Security Service and in FortiGate GUI as Attack Surface Security Rating.

 

FortiCloud shows FortiGuard Attack Surface Security Service for FGT.png

 

FGT license Security Rating Update.png

 

  1. Configuration for FortiAnalyzer log setting in FortiGate makes sure certificate-verification are is enabled.

 

FGT-HUB # config log fortianalyzer setting

    set status enable
    set server "x.x.x.x"
    set serial "FAZVMSXXXXXXX"
    set upload-option realtime
    set reliable enable

    set certificate-verification enable  --> Enable this configuration.
end

 

  1. Check that the Security Rating in FortiGate populates an output under Security Fabric -> Security Rating.

 

FGT Security Rating output.png

 

  1. Confirm that there are logs generated in FortiGate under Log & Report -> System Events -> Logs -> Select dropdown (Security Rating Events).

event logs in FGT.png

 

  1. Confirm that the same logs are present in FortiAnalyzer under Log View -> Logs -> Fortinet Logs -> FortiGate -> Event: Security Rating (FortiAnalyzer in v7.6.4).

 

event logs in FAZ.png

 

  1. Run the report again, and make sure the Settings of the report contain the same time and date as the logs populated in the Log View before (Device selection also needs to make sure it is the same as the individual FortiGate if selected to get consistent output from the report).

 

security posture populate output.png

fabric coverage populate output.png

 

optimization populate output.png