FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
haziqsulaiman
Article Id 416694
Description

This article describes a scenario where FortiOS Connector in FortiAnalyzer is not populated, and the configuration that can be checked on FortiGate to troubleshoot the issue.

Scope FortiGate, FortiAnalyzer.
Solution

From the image below, Automation Stitch with webhook trigger is already configured in FortiGate.

 

1. automation.png

 

However, in FortiAnalyzer, the stitch is not seen.

 

2. connector.png

 

To troubleshoot this, check the Logging & Analytics configuration in FortiGate under Security Fabric -> Fabric Connectors > Logging & Analytics. Ensure the settings 'Allow access to FortiGate REST API' and 'Verify FortiAnalyzer certificate' are set to enable.

 

3. logging.png

 

After a few minutes, the connector can be seen in FortiAnalyzer.

 

4. connector_visible.png

 

Related article:

Troubleshooting Tip: Troubleshooting FortiOS connector red/disconnected status