Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Stan_O_
New Contributor

LDAP Queries with FortiAnalyzer

Does there exist any documentation with a degree of completeness regarding reporting using LDAP queries?  Or any primer another end-user can provide that might help me get it working.

 

I've read the following posts and followed all suggestions contained within (including the brief mentions of LDAP within the FortiAnalyzer documentation) to no avail:

https://forum.fortinet.com/tm.aspx?m=74665

https://forum.fortinet.com/tm.aspx?m=115766

https://forum.fortinet.com/tm.aspx?m=115241

 

The _FTNT responses make it sound simple, but it really appears to not work and the documentation is quite minimal.

 

I have 20 days left on my evaluation, and reporting by LDAP Group is the primary reason for potentially purchasing the product after the evaluation expires.

 

Thanks,

 

Stan

1 REPLY 1
Stan_O_
New Contributor

While troubleshooting this issue, I noticed the log files on the FAZ for my FortiGate device were being purged daily, which seemed odd. Drilling down, I found that the Disk Log Quota for our FortiGate was set to only 1000MB. Once I raised this value (initially to 10000MB), the LDAP reporting functionality began working as expected with the configuration described in the post above.  

 

I took a VMware snapshot of the working appliance then rebooted and set the Disk Log Quota back to 1000MB and confirmed the LDAP reporting no longer functioned correctly after the vAppliance had purged the logs to satisfy the device log quota requirements.

 

Stepping through the Add Device process on the FAZ, I see the default Disk Log Quota is 1000MB when a device is added.  This value should probably be raised so this situation can be avoided by future new users.  Now that the device is functioning, it's clear the Disk Log Quota refers to the cumulative quota (max 200GB per device for the base FAZ-VM), not the daily device quota (1GB (1000MB)/day for the base FAZ-VM).

 

Thanks for reading,

 

Stan

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors