Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Chris_Colantonio
New Contributor

Log access via FG stopped after upgrade.

Since I upgraded to 4.0MR1 patch3 on my FG620b, (from the FG GUI: log access--> Fortianalyzer tab), I can only see logs with a timestamp of shortly before the upgrade. The strange thing is that I can see current logs if I view directly from fortianalyzer gui...so the info is getting collected. This isn' t high priority, but it is nice to have the current logs accessible from the FG. Did I miss something in the release notes? Thanks in advance, Chris C.
___________________ FCNSA 3.0 2 FG-620b HA 2 FWF-60B FortiAnalyzer 2000a FortiMail 400
___________________ FCNSA 3.0 2 FG-620b HA 2 FWF-60B FortiAnalyzer 2000a FortiMail 400
10 REPLIES 10
rwpatterson
Valued Contributor III

What firmware is on the FAZ?

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Chris_Colantonio
New Contributor

Thanks for looking into this so quickly! FA-2000A is on v4.0,build0133 (MR1 Patch4) and forgot to mention that it was also upgraded the same day as the firewall.
___________________ FCNSA 3.0 2 FG-620b HA 2 FWF-60B FortiAnalyzer 2000a FortiMail 400
___________________ FCNSA 3.0 2 FG-620b HA 2 FWF-60B FortiAnalyzer 2000a FortiMail 400
rwpatterson

Where did you upgrade from? Did you follow the proper path?

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Chris_Colantonio
New Contributor

I don' t know the version off the top of my head, but I definitely followed upgrade path according to release notes. I just noticed that even from the FA, I can only see the real-time new logs. When I look at historical, only pre-upgrade logs are showing. Also, not sure if this is related but the 620' s are in HA-AA and during the firmware upgrade the secondary unit apparently wasn' t turned on. It is on now. Could that be an issue? Can I check if the 2ndary unit' s firmware was upgraded when powered up? Chris C.
___________________ FCNSA 3.0 2 FG-620b HA 2 FWF-60B FortiAnalyzer 2000a FortiMail 400
___________________ FCNSA 3.0 2 FG-620b HA 2 FWF-60B FortiAnalyzer 2000a FortiMail 400
rwpatterson

When I upgraded from 3x to 4x, I had to go into Application Control and re-enable logging in there. (if I can recall correctly...)

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Chris_Colantonio
New Contributor

It is still enabled for apps that is supposed to be. Plus, it' s not just app logs that I' m missing, it' s all logs (edit: all logs from FG...other devices ie. fortimail and syslog are fine). Following that logic, I unchecked all the logging in the protection profile, saved and re-enabled...did not fix it. This is a bit more critical now that I can' t see historicals. I' ll open up a ticket and update the post with the progress.
___________________ FCNSA 3.0 2 FG-620b HA 2 FWF-60B FortiAnalyzer 2000a FortiMail 400
___________________ FCNSA 3.0 2 FG-620b HA 2 FWF-60B FortiAnalyzer 2000a FortiMail 400
Chris_Colantonio
New Contributor

Update: The issue has been identified as FAZ bug #121292. Bob, Thanks for giving it a go...
___________________ FCNSA 3.0 2 FG-620b HA 2 FWF-60B FortiAnalyzer 2000a FortiMail 400
___________________ FCNSA 3.0 2 FG-620b HA 2 FWF-60B FortiAnalyzer 2000a FortiMail 400
darrencarr
New Contributor II

Hi Chris I have a similar issue with my historical logging. I don' t see anything in my historical log for my Fortigate devices. I recently upgraded to v4.0,build0133 (MR1 Patch 4) Reviewing the release notes for this patch this bug ID does not appear in the notes. Do you have any information from Fortinet when the next release is likely to be? I think this may be related to an issue I currently have relating to SSL-VPN reporting. Thanks Darren
Fortigate 1000A v4.0,build194,100121 (MR1 Patch 4) Fortianalyzer 800B v4.0,build0130 (MR1 Patch 3)
Fortigate 1000A v4.0,build194,100121 (MR1 Patch 4) Fortianalyzer 800B v4.0,build0130 (MR1 Patch 3)
Chris_Colantonio

Hi Darren, I found it interesting that bug was not in the release notes as well. :( I can' t get into the details...but looks like the fix will be out in the next version release within a few weeks. That being said, I highly suggest you create a ticket if the issue is urgent. Chris C.
___________________ FCNSA 3.0 2 FG-620b HA 2 FWF-60B FortiAnalyzer 2000a FortiMail 400
___________________ FCNSA 3.0 2 FG-620b HA 2 FWF-60B FortiAnalyzer 2000a FortiMail 400
Labels
Top Kudoed Authors