FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
markwarner
Staff
Staff
Article Id 269211
Description

 

This article describes how to fix a possible cause behind the 'Top Source Addresses' and 'Top Destination Addresses' showing "no record found" in FortiView while the other sections do.

 

no logs.png

 

Scope

 

All supported versions of FortiAnalyzer.

 

Solution

 

These charts rely on the source and destination UUIDs in FortiGate traffic logs.
The option on the FortiGate is disabled by default as the UUID strings are quite long and will increase the disk usage when enabled.

To enable UUID logging from the FortiGate, go to Log & Report -> Log Settings -> UUIDs in Traffic Log and enable the option.

 log setting.JPG
The corresponding CLI configuration on FortiGate is as follows:

 

config system global
    set log-uuid-address enable
end