FortiSIEM
FortiSIEM provides Security Information and Event Management (SIEM) and User and Entity Behavior Analytics (UEBA)
lucianag22
Staff
Staff
Article Id 419128
Description This article explains why is not available Advanced Search Tab under Analytics.
Scope FortiSIEM v7.3.0 and higher.
Solution

V7.3.0 was released with the feature Advanced Search to run generic SQL queries against the ClickHouse event database; therefore, it is not possible to see the Advanced Search Tab under Analytics is due event database is different from ClickHouse.

 

Verify using the 'df -h' command by SSH or checking the storage information in the banner at the bottom:

 ScreenshotAS.png

 

If EventDB Local Disk or EventDB NFS is being used as storage is not possible to use this feature as they use a proprietary NoSQL database. When event data is migrated to ClickHouse, the feature becomes available.

 

Screenshot 2025-11-14 145824.png

 

Related documents:

Changing EventDB to ClickHouse 

Advanced ClickHouse Search 

Contributors