FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
mkannan
Staff
Staff
Article Id 194220

Description

 
This article describes how to connect FortiWeb to a FortiAnalyzer Device or VM.


Scope

 
FortiWeb and FortiAnalyzer.


Solution:

 

On the FortiWeb:
 
  1. Configure FortiWeb with FortiAnalyzer IP.

  • Go to Log & Report -> Log Policy -> FortiAnalyzer Policy.
  • Create a new policy.
  • Set Name.
  • Set FortiAnalyzer IP.
  • Select 'OK'.

84.png

 

  1. Configure FortiAnalyzer Log Settings.
     
  • Go to Log & Report -> Log Config -> Global Log Settings.
  • Enable the FortiAnalyzer [Checkbox].
  • Specify 'Log Level' as 'Information'.
  • Specify 'FortiAnalyzer Policy' as 'FAZ' [The name FortiAnalyzer policy created in the previous step].
  • Select 'Apply'.

85.png

 

 
On the FortiAnalyzer.
 
  1. ADOM Configuration.

  • Enable the ADOM.

mkannan_FD40249_tn_FD40249-3.jpg

  1. Device Registration.
     
  • Go to Root-ADOM -> Device Manager -> Unregistered device ->

mkannan_FD40249_tn_FD40249-4.jpg
 
  • After selecting 'OK' the device will be added, verify the status and select 'CLOSE'.

mkannan_FD40249_tn_FD40249-5.jpg

  • Login to the FortiWeb ADOM:

mkannan_FD40249_tn_FD40249-6.jpg

There is another option to aggregate FortiWeb to FortiAnalyzer.
 
  1. Creating New ADOM.

 

  • Go to System Settings -> ADOMs -> Create New.
  • Set Name.
  • Select Type: FortiWeb.
  • Keep all other settings with Default Values.
  • Select 'OK'.

86.png

 

  1. Change to New FortiWeb ADOM to aggragate FortiWeb.

     

    • Go to Dashboard -> Select the ADOM Button.

    88.png

    • Select New FortiWeb ADOM created.

    89.png

     

     

  2. Configure FortiWeb in FortiAnalyzer -> Device Manager.

     

    • Go to Device Manager.
    • Select: Add Device.

    90.png

     

    • Set Name.
    • Select Link Device by: Serial Number.
    • Set FortiWeb Serial Number.
    • Select FortiWeb Device Model.
    • Select 'Next'.

     

    91.png

     

    • A New Database is created and FortiWeb will be aggregated.
    • Select 'Next' to finish.

     

    92.png

     

    • It is possible to see the wrong Version and Model, it is normal, FortiAnalyzer and FortiWeb need to complete the synchronization.

    93.png

     

    • After a few seconds, it it possible to see FortiWeb's correct information.

    94.png