I inherited a Fortigate 800C and FortiAnalyzer 100B - and I am pretty sure the Analyzer is not working right.
On the Fortigate, the "Send Logs to FortiAnalyzer" is checked, the IP Address is right, test connectivity shows all is ok. "Enable all" is checked for event logging
On the Analyzer, under Devices it shows the Fortigate Unit, has check marks for all permissions and shows "Data was received on 2015-01-12" and 8gb of logs are in use. In the summary list of devices, the "logs" column shows a green light.
On the Analyzer, When I go into "Log and Archive" and select "Traffic Log" I see screens of traffic events
But I don't seem to get anything. When I go to reports-Bandwidth and App Usage: "Top Users by Sessions" and "Top applications by sessions" have bar charts, but all the rest just say "No Data"
In the "Web Usage", Threats", Predefined Reports" etc. all of the charts just say "No Data"
it is running 4.0 MR3 patch 8 ( which is the last version for the 100B )
Does this sound familiar to anyone? Any help would be appreciated
Mark
(error, sorry)
AtiT
no luck. I don't seem to have ADOMS because there isn't a "Config Global" option. I am logged in as admin so I shoul dnot have a administrative domain problem:
FortiAnalyzer-100B # config ?
backup backup
connectwise connectwise
gui gui
log log
nas nas
netscan Network vulnerability scanner configuration
report report
sql-report sql-report
system system
FortiAnalyzer-100B #
I was able to run the following commands. We will see if that does anything:
FortiAnalyzer-100B # execute sql-local remove-db
The entire local SQL database will be removed!
Do you want to continue? (y/n)y
Processing...................................
Local SQL database is successfully removed.
FortiAnalyzer-100B # execute reset-sqllog-transfer
Hello,
this is a compatibility problem
I was afraid of that....
If that is the case, I have 2 choices:
1) backrev my Fortigate to 4.0 MR3 patch 8 so I can use the Fortianalyzer
2) toss the Fortianalyzer in the garbage
Sadly the 3rd option (upgrade the Fortianalyzer to match the Fortigate) doesn't seem to be possible since Fortinet capped the 100B at 4
Mbutler522010 wrote:I was afraid of that....
If that is the case, I have 2 choices:
1) backrev my Fortigate to 4.0 MR3 patch 8 so I can use the Fortianalyzer
2) toss the Fortianalyzer in the garbage
Sadly the 3rd option (upgrade the Fortianalyzer to match the Fortigate) doesn't seem to be possible since Fortinet capped the 100B at 4
Sorry to hear that. FAZ 100B is a very old hardware platform with limited CPU and Memory. It simply cannot run the newer firmware.
we recently purchase forti analyzer 200d and installed it, we are getting logs on forti analyzer but we can't able to generate any report, when we run the report and download the pdf it doesn't show any log, but if i go to forti view option we are able to see log. i opened the reports tab, and click on user report or any other type of report then click the run report and then download it but it give us empty report.
m.raza
There are a lot of possibilities to go wrong with the Fortigate-Fortianalyzer combo.
First check your System Settings tab and look at the "Log Receive Monitor" and make sure it shows logs are being received.
If it does not show them being received, you will need to check the setup on your Fortigate.
Also check that you are getting usable data to the Fortianalyzer. If you go to the "FortiView" tab and get nothing (like screenshot) then data is not flowing properly and it is time to call tech support.
if you are showing data in the FortiView tab, ensure your report has the proper configuration. Go to the configuration tab on the report and make sure it says "all devices:"
if all of that looks good and you are getting nothing in the reports, I recommend opening a ticket with tech support.
Mark
Is there a way to generate a FortiAnalyzer report that shows the time of day, and the name of the website visited, for a specified user? I've looked around in the chart library and dataset, but can't seem to figure out how to do it.
You can easily have a report for a specific user, on settings tab of your report, "Filter" or something like that where you can set username
Case maybe be sensitive ( I don't remember)
2 FGT 100D + FTK200
3 FGT 60E FAZ VM some FAP 210B/221C/223C/321C/421E
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1744 | |
1114 | |
760 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.