Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
c1live
New Contributor

Fortianalyzer v7.6.3 WiFi Rogue APs reporting

Am hoping someone can shortcut me to a solution. About a year back we moved to a new office, introduced a new FG120G firewall, logs are sent to our existing FAZ-VM running v7.6.3 firmware.

Because of PCI DSS Compliance we have a custom report which is supposed to give us a list of potentially harmful WiFi APs in/near our environment. That report does give me some data. e.g. a list of APs detected with a signla strength greater than -75dBm.

However the report also used to give data about On-Wire and Off-Wire APs, those which I had classified as Accepted, those which were designated Rogue, etc. That data came from built-in Charts / Datasets from some previous version of the Fortianalyzer.

At some point since we left our old office (about 3 years ago) and getting our new office (about 1 year ago), these built-in Charts / Datasets apparently just stopped working. It appears to me that all the On-Wire, Off-Wire, etc charts/datasets have just stopped producing data.

Has anyone noticed and/or tried to tackle this issue? When I check the underlying datasets, the queries compile/run okay, just no data when you look at the charts using those datasets.

10.0.0.0.1 192.168.1.254
3 REPLIES 3
Jean-Philippe_P
Moderator
Moderator

Hello c1live, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

 

Thanks, 

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Moderator
Moderator

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

 

Thanks,

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Moderator
Moderator

Hello c1live,

 

I found a solution. Can you tell me if it helps, please?

 

To address the issue of missing data in your custom report on FortiAnalyzer, follow these steps:

 

  1. Verify Log Availability: Ensure that the necessary logs are being sent from the FortiGate to the FortiAnalyzer. Check if the logs related to on-wire and off-wire APs are being generated and received.

  2. Check Dataset Configuration: Review the datasets used in your report. Ensure that they are correctly configured to query the relevant log types and data sources. Verify that the datasets are referencing the correct log fields.

  3. Report Guidance Feature: Use the Report Guidance feature in FortiAnalyzer to troubleshoot the report. This feature can help confirm if the required analytics logs are available and identify any issues with the report configuration.

  4. ADOM Configuration: If you are using ADOMs, ensure that you are in the correct ADOM and that the datasets, charts, and macros are correctly configured for that ADOM. Verify that the device types supported by the ADOM are compatible with the datasets.

  5. Common Issues: Refer to common issues that may cause empty charts, such as wrong report filters, log field changes after upgrades, or hcache corruption. Clear the hcache if necessary using the command `diagnose sql remove hcache`.

  6. Log Version: Check if the datasets are using the "logver" field to identify the FortiOS log version. Ensure that the logs are compatible with the current FortiAnalyzer version.

  7. Dataset Test Console: Use the dataset test console or SQL debug to identify any issues with the dataset queries.

 

If the issue persists after following these steps, consider reaching out to Fortinet support for further assistance.

Jean-Philippe - Fortinet Community Team
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors