Hi,
First of all, sorry for my English, it's not my first language.
I upgraded my Fortigate 80C to v5.2.2 build 642 and my FortiAnalyzer 100C to v5.2.1 build 0662. And after this, there is no data in my FortiAnalyzer. In every report that I generate, there is always "no data". In Fortiview Menu, in every category there is "No entry found". And in "Log Receive Monitor" it shows like FortiAnalyzer apparently is receiving logs correctly.
In Fortigate, is marked to send logs to fortianalyzer, and the Test Connection is ok. And in FortiAnalyzer, in Device Manager Section, it appears my Fortigate with a green light in column "Logs" which means, I suppos that is correct.
Do you have any idea??
Thank you in advance!
What was the previous FAZ firmware version that you upgraded from? The symptoms you provided there made me think the log database is rebuilding...
Try to run the following command from the CLI to check the SQL database status: diagnose sql status rebuild-db
Hello,
The previous version was v4.0 MR3 Patch 8.
The result of the command you comment is:
"Rebuilding log SQL database accomplished on
Tue Jan 13 09:53:31 2015"
This was the time when I upgraded.
But now I see that the CPU Usage is 100% for at least 5 or 6 hours, and maybe more hours because I didn't see it before. Maybe is because are rebuilding the sql db...
Thank you!
Hello-
Is your 80C in the default ADOM of "root"? If so, create an ADOM with set to handle Firmware Version 5.2, add your 80C to that ADOM and see if that resolves the problem.
Upgrade from 4.x to 5.x does require SQL rebuild. After the rebuild completed, it will have some catch up work to do.. processing the new logs and get them into the database as fast as it can...
I believe next release 5.2.2 will show the rebuilding progress in the GUI so the admin would know what is going on in the system after the upgrade.
Ok, I will wait a few hours or days. Maybe it is finishing the rebuild.
I will comeback with news.
Thank You!
Good news! After 5 days, Fortianalyzer is running. The CPU usage is at 40% and the reports starts to show information. So I suppose that these days Fortianalyzer was rebuilding the db or something like that. Thank for your help!
User | Count |
---|---|
1923 | |
1144 | |
769 | |
447 | |
279 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.