Description | This article describes how to resolve an issue where FortiWeb is not sending the attack logs to FortiAppSec however the status of the threat analytic is up and connected. |
Scope | FortiWeb. |
Solution |
Step 1: Verify that FortiWeb is successfully generating the attack logs: Under Log & Report -> Log Config -> Global Log Settings: verify that Attack log is marked with log level of 'Information'. Under Log & Report -> Log Access -> Attack log: verify that the attack logs are being generated.
Step 2: In the Dashboard, select Threat Analytics in the system information widget, then log in to the AppSec account.
Step 3: Verify the Threat Analytics connectivity:
diagnose system threat-analytics info WS Connection: Connected =========> Here the status is "connected"
Step 4: Packet capture the connection between FortiWeb and FortiAppSec on port 9194:
In the above example, the SYN packets are being sent out of FortiWeb but the SYN-ACKs are not being received back. This can be resolved by allowing port 9194 on the Firewall. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.