Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mitch
New Contributor

FAZ 5.0.1 - All Web Filter charts return " No Data to Display

Hi guys, I' ve recently upgraded the firmware on my FAZ to v5.0-build0087 121121 (GA Patch 1). Did a complete format and have 150+ devices logging data successfully. I can see logs being collected for every type and subtype within the Log View tab. The reports, and RTM profiles load and visualises the data great. HOWEVER! Anything related to the web filter logs return " No Data to Display" ... on every chart. The FAZ has been collecting data for days now, with each device having 30000+ rows in the Web Filter log and others. Attempting to create my own dataset to see the ' raw' logs was also unsuccessful.
select * from $log where $filter LIMIT 20
Applying this data set to a new, basic tabled chart yields Loading data error. I have attempted changing the Time Periods on the RTM Profiles and also on the UTM Security Analysis report to no avail. The reporting is so much more visually appealing I don' t want to downgrade back to v4. HELP PLEASE
20 REPLIES 20
scao_FTNT
Staff
Staff

can you see " Web Filter" log files in " Log View" - " Log Browse" ? Thanks Simon
mitch
New Contributor

I can see logs being collected for every type and subtype within the Log View tab.
Yep! There are several thousand " Web Filter" logs for each device under " Log View" .
mitch
New Contributor

Ladies and Gents, I have just stumbled across Bug ID 186525: The FortiAnalyzer may fail to produce charts for Top Allowed Websites by Bandwidth, Top Viruses by Name, or Top Viruses Victims. I think I was a bit too keen on the update firmware gun. Does anyone have an ETA on Patch 2?
rulirahm
New Contributor

From Support:
The next patch release is scheduled by end of next month (January 2013) but it' s subject to change if there' s any critical bug issue. Please be informed.
seadave
Contributor III

I' m in the same boat. Fortunately I' m only trying to monitor a 100D, but my FAZ100C (both are running 5.01) is essentially a glorified syslog viewer at this point. Reports do not work, host IPs are not resolved (external), and the overall performance is sloppy and inconsistent. I guess I should have learned from the past and left it on 4.3 until 5.0 was on 5.1 but I succumbed to the " Revolutionary" Fortinet advertising.
Rick_H
New Contributor III

I' m bumping up against this same exact problem. I' m not sure if it makes a difference, but we had the SQL database disabled in v4MR3 and were just using traditional log-based reporting instead prior to the upgrade. Was this the case for anyone else? Has support given anyone a work-around? We upgraded for the supposedly superior reporting functionality and now we need those reports for our end-of-year IT reporting.
mitch
New Contributor

The only work around I' ve had from support is to wait for 5.0.2. I was planning to downgrade back to v4.3 so I could utilise the reporting functionality - which is why I have a FAZ , but alas 5.0.1 does not support any execute backup or execute restore functionality (Bug ID: 0180601). I too am very interested if anyone else is in the same boat with a workaround? And I' ll be reading the known issues within the release notes twice before upgrading to a newer firmware - although upgrading to 5.0.1 feels more like a downgrade thus far!
rulirahm
New Contributor

Hi Guys, I don' t have any experience about downgrade. If I just downgrade FAZ 5.0.1 to 4.3 without back up logs & reports, what will happens? Am I gonna loss all logs & reports? Regards, Ruli
mitch
New Contributor

Any news on the 5.0.2 release? Is there a list of fixes we can expect to see? I' m sure it' ll be a long one!
Labels
Top Kudoed Authors