Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Mbutler522010
New Contributor

"No Data" on most of the reports

I inherited a Fortigate 800C and FortiAnalyzer 100B - and I am pretty sure the Analyzer is not working right.

 

On the Fortigate, the "Send Logs to FortiAnalyzer" is checked, the IP Address is right, test connectivity shows all is ok. "Enable all" is checked for event logging

 

On the Analyzer, under Devices it shows the Fortigate Unit, has check marks for all permissions and shows "Data was received on 2015-01-12" and 8gb of logs are in use. In the summary list of devices, the "logs" column shows a green light.

 

On the Analyzer, When I go into "Log and Archive" and select "Traffic Log" I see screens of traffic events

 

But I don't seem to get anything. When I go to reports-Bandwidth and App Usage: "Top Users by Sessions" and "Top applications by sessions" have bar charts, but all the rest just say "No Data"

 

In the "Web Usage", Threats", Predefined Reports" etc.  all of the charts just say "No Data"

 

it is running 4.0 MR3 patch 8 ( which is the last version for the 100B )

 

Does this sound familiar to anyone? Any help would be appreciated

Mark

 

 

21 REPLIES 21
AtiT
Valued Contributor

(error, sorry)

AtiT

AtiT
Mbutler522010

no luck. I don't seem to have ADOMS because there isn't a "Config Global" option. I am logged in as admin so I shoul dnot have a administrative domain problem:

FortiAnalyzer-100B # config ?

 

backup        backup  

connectwise   connectwise  

gui           gui  

log           log  

nas           nas  

netscan       Network vulnerability scanner configuration  

report        report  

sql-report    sql-report  

system        system
FortiAnalyzer-100B #

 

 

I was able to run the following commands. We will see if that does anything:

FortiAnalyzer-100B # execute sql-local remove-db
The entire local SQL database will be removed!
Do you want to continue? (y/n)y

Processing...................................
Local SQL database is successfully removed.

FortiAnalyzer-100B # execute reset-sqllog-transfer

npesct
New Contributor

Hello,

 

this is a compatibility problem

 

Mbutler522010

I was afraid of that....

 

If that is the case, I have 2 choices:

1) backrev my Fortigate to 4.0 MR3 patch 8 so I can use the Fortianalyzer

2) toss the Fortianalyzer in the garbage

 

Sadly the 3rd option (upgrade the Fortianalyzer to match the Fortigate) doesn't seem to be possible since Fortinet capped the 100B at 4

 

L_FTNT

Mbutler522010 wrote:

I was afraid of that....

If that is the case, I have 2 choices:

1) backrev my Fortigate to 4.0 MR3 patch 8 so I can use the Fortianalyzer

2) toss the Fortianalyzer in the garbage

Sadly the 3rd option (upgrade the Fortianalyzer to match the Fortigate) doesn't seem to be possible since Fortinet capped the 100B at 4

Sorry to hear that. FAZ 100B is a very old hardware platform with limited CPU and Memory. It simply cannot run the newer firmware. 

Ling Lu
m_raza
New Contributor

we recently purchase forti analyzer 200d and installed it, we are getting logs on forti analyzer but we can't able to generate any report, when we run the report and download the pdf it doesn't show any log, but if i go to forti view option we are able to see log. i opened the reports tab, and click on user report or any other type of report then click the run report and then download it but it give us empty report.

Mbutler522010

m.raza

There are a lot of possibilities to go wrong with the Fortigate-Fortianalyzer combo.

First check your System Settings tab and look at the "Log Receive Monitor" and make sure it shows logs are being received.

 

If it does not show them being received, you will need to check the setup on your Fortigate.

 

Also check that you are getting usable data to the Fortianalyzer. If you go to the "FortiView" tab and get nothing (like screenshot) then data is not flowing properly and it is time to call tech support.

 

if you are showing data in the FortiView tab, ensure your report has the proper configuration. Go to the configuration tab on the report and make sure it says "all devices:"

 

if all of that looks good and you are getting nothing in the reports, I recommend opening a ticket with tech support.

Mark

m_raza

Is there a way to generate a FortiAnalyzer report that shows the time of day, and the name of the website visited, for a specified user?   I've looked around in the chart library and dataset, but can't seem to figure out how to do it.  

Baptiste

You can easily  have a report for a specific user, on settings tab of your report, "Filter" or something like that where you can set username

Case maybe be sensitive ( I don't remember)

2 FGT 100D  + FTK200

3 FGT 60E  FAZ VM  some FAP 210B/221C/223C/321C/421E

2 FGT 100D + FTK200 3 FGT 60E FAZ VM some FAP 210B/221C/223C/321C/421E
m_raza

i am filtering with proper username but it still show empty report

Labels
Top Kudoed Authors