Hello guys ,
I have a problem with reports from FortiAnalyzer.
I'm gonna explain my 'topology' the best way i can.
Firstly, there is a standalone EMS that pushes the logs of the hosts to the FortiAnalyzer. I can see the logs in Fortianalyzer , so we are sure that we have them in the right place and there isnt a conneciton problem.
It seems that when i run a report (new or old) it's contents its the same almost every time and there is only one host in its results. I use the default report editor (i have tried use different choices in the graphs but no desired result). Also i give it a try with and without the extended log filtering and checked all the options (device , source ip, dest ip, endpoint id....). Enable High Accuracy Caching also checked in case there is a problem with the number of logs.
FortiAnalyzer uses ADOM (the correct one selected) , version v7.6.3 build3492 (Feature)
User | Count |
---|---|
2570 | |
1362 | |
796 | |
651 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.