Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
infor_act
New Contributor

No Data in FortiAnalyzer

Hi,

First of all, sorry for my English, it's not my first language.

 

I upgraded my Fortigate 80C to v5.2.2 build 642 and my FortiAnalyzer 100C to v5.2.1 build 0662. And after this, there is no data in my FortiAnalyzer. In every report that I generate, there is always "no data". In Fortiview Menu, in every category there is "No entry found". And in "Log Receive Monitor" it shows like FortiAnalyzer apparently is receiving logs correctly.

In Fortigate, is marked to send logs to fortianalyzer, and the Test Connection is ok. And in FortiAnalyzer, in Device Manager Section, it appears my Fortigate with a green light in column "Logs" which means, I suppos that is correct.

 

Do you have any idea??

Thank you in advance!

6 REPLIES 6
L_FTNT
Staff
Staff

What was the previous FAZ firmware version that you upgraded from? The symptoms you provided there made me think the log database is rebuilding...

Try to run the following command from the CLI to check the SQL database status: diagnose sql status rebuild-db

 

Ling Lu
infor_act
New Contributor

Hello,

 

The previous version was v4.0 MR3 Patch 8.

The result of the command you comment is:

"Rebuilding log SQL database accomplished on

Tue Jan 13 09:53:31 2015"

This was the time when I upgraded.

 

But now I see that the CPU Usage is 100% for at least 5 or 6 hours, and maybe more hours because I didn't see it before. Maybe is because are rebuilding the sql db...

 

Thank you!

Matt_Garrett
New Contributor

Hello-

 

Is your 80C in the default ADOM of "root"?  If so, create an ADOM with set to handle Firmware Version 5.2, add your 80C to that ADOM and see if that resolves the problem.

 

 

L_FTNT
Staff
Staff

Upgrade from 4.x to 5.x does require SQL rebuild. After the rebuild completed, it will have some catch up work to do.. processing the new logs and get them into the database as fast as it can...

 

I believe next release 5.2.2 will show the rebuilding progress in the GUI so the admin would know what is going on in the system after the upgrade.

Ling Lu
infor_act
New Contributor

Ok, I will wait a few hours or days. Maybe it is finishing the rebuild.

I will comeback with news.

 

Thank You!

 

infor_act
New Contributor

Good news! After 5 days, Fortianalyzer is running. The CPU usage is at 40% and the reports starts to show information. So I suppose that these days Fortianalyzer was rebuilding the db or something like that. Thank for your help!

Labels
Top Kudoed Authors