Fortinet black logo

Known Issues

Known Issues

The following issues have been identified in FortiAnalyzer version 6.2.6. For inquires about a particular bug or to report a bug, please contact Fortinet Customer Service & Support.

Device Manager

Bug ID Description
613115 Device Manager view may show red icons for VDOMs even when the log is received.

FortiSoC

Bug ID Description
638676 SNMP alert is not generated for event handler triggered by FortiWeb attack logs.

FortiView

Bug ID

Description

565778 FortiAnalyzer may prompt empty SOC website related to dashboard while the web filter logs exist.
579828 There may be bandwidth discrepancy under FortiView > Application & websites > Top websites.
590775 FortiAnalyzer should hide Device and Time Frame selection in FortivView Threat Map.
616675 Bandwidth may not match between FortiAnalyzer and FortiGate.
636361 The selected time range may not correspond with the time range in the charts for the Resource Usage drilldown.
638828 Incident of Compromised Hosts may not be triggered.
640553 FortiView monitor WiFi widget is not showing Bridged SSID information.
641938 The GUI many not respond when navigating to Monitors > Local System Performance.
616914 Some graphs may not render data in FortiView.

Log View

Bug ID Description
591272 Downloading log files from Log View or Browse are not exported in the correct CSV format.
604850 The remote IP for SSL-VPN is showing as IPsec Remote IP.
625306 Hiding column(s) in Log View may cause the filters to reference the wrong column.
633393

Some IPS archive files only contain the BODY instead of showing the entire Attack Context .

635598 FortiAnalyzer may not display Traffic Logs in Log View and return Web Server Error 500.
638388 When two filters are defined and the first filter is removed, clicking on the remaining filter may reference the filter that was removed.
641013 After creating an ADOM for FortiMail, the ADOM is not visible on the GUI and mail domain logs are not going to the default FortiMail ADOM.
643858 Actual analytic logs do not match what is observed in Log View.
652076 Log View may load infinitely with Custom Time Period.
656441 Downloading an uncompressed CSV format log prompts web server error 500.

Others

Bug ID Description
595696 Changing the value for system.global.enc-algorithm is not applied to oftpd until a reboot.
617669 File parser may keep crashing every few minutes.
622408 FortiAnalyzer may consume high disk I/O resource and high throughput may cause high CPU usage.
625343 FortiAnalyzer may consume high usage on I/O resources every hour due to fazwatch.

Reports

Bug ID Description
624911 FortiAnalyzer may not be able to generate the SaaS Application Usage Report with Obfuscate User feature.
628823 FortiAnalyzer is not generating all local Event logs for reports.
647868 After upgrade, all default reports and event handler lists are lost.
652715 The pre-defined reports items should be created in the new ADOM even if the same name being re-used.
653532 Scheduled report does not run if the report owner has been deleted from the admin list.
654182 SD-WAN reporting graphs default to a scale of one second where the scale should auto-scale to milliseconds.

System Settings

Bug ID

Description

629663 Free text filter does not work when using (~) tilde sign on syslog ADOM for the msg field.
634253 ADOMs may disappear randomly from ADOM configuration while editing it.
639102 FortiAnalyzer may not apply Not equal to operator when Log Forwarding > Log Filter is configured with the GUI.
653371 CEF log forwarding start time does not match with event time.

Known Issues

The following issues have been identified in FortiAnalyzer version 6.2.6. For inquires about a particular bug or to report a bug, please contact Fortinet Customer Service & Support.

Device Manager

Bug ID Description
613115 Device Manager view may show red icons for VDOMs even when the log is received.

FortiSoC

Bug ID Description
638676 SNMP alert is not generated for event handler triggered by FortiWeb attack logs.

FortiView

Bug ID

Description

565778 FortiAnalyzer may prompt empty SOC website related to dashboard while the web filter logs exist.
579828 There may be bandwidth discrepancy under FortiView > Application & websites > Top websites.
590775 FortiAnalyzer should hide Device and Time Frame selection in FortivView Threat Map.
616675 Bandwidth may not match between FortiAnalyzer and FortiGate.
636361 The selected time range may not correspond with the time range in the charts for the Resource Usage drilldown.
638828 Incident of Compromised Hosts may not be triggered.
640553 FortiView monitor WiFi widget is not showing Bridged SSID information.
641938 The GUI many not respond when navigating to Monitors > Local System Performance.
616914 Some graphs may not render data in FortiView.

Log View

Bug ID Description
591272 Downloading log files from Log View or Browse are not exported in the correct CSV format.
604850 The remote IP for SSL-VPN is showing as IPsec Remote IP.
625306 Hiding column(s) in Log View may cause the filters to reference the wrong column.
633393

Some IPS archive files only contain the BODY instead of showing the entire Attack Context .

635598 FortiAnalyzer may not display Traffic Logs in Log View and return Web Server Error 500.
638388 When two filters are defined and the first filter is removed, clicking on the remaining filter may reference the filter that was removed.
641013 After creating an ADOM for FortiMail, the ADOM is not visible on the GUI and mail domain logs are not going to the default FortiMail ADOM.
643858 Actual analytic logs do not match what is observed in Log View.
652076 Log View may load infinitely with Custom Time Period.
656441 Downloading an uncompressed CSV format log prompts web server error 500.

Others

Bug ID Description
595696 Changing the value for system.global.enc-algorithm is not applied to oftpd until a reboot.
617669 File parser may keep crashing every few minutes.
622408 FortiAnalyzer may consume high disk I/O resource and high throughput may cause high CPU usage.
625343 FortiAnalyzer may consume high usage on I/O resources every hour due to fazwatch.

Reports

Bug ID Description
624911 FortiAnalyzer may not be able to generate the SaaS Application Usage Report with Obfuscate User feature.
628823 FortiAnalyzer is not generating all local Event logs for reports.
647868 After upgrade, all default reports and event handler lists are lost.
652715 The pre-defined reports items should be created in the new ADOM even if the same name being re-used.
653532 Scheduled report does not run if the report owner has been deleted from the admin list.
654182 SD-WAN reporting graphs default to a scale of one second where the scale should auto-scale to milliseconds.

System Settings

Bug ID

Description

629663 Free text filter does not work when using (~) tilde sign on syslog ADOM for the msg field.
634253 ADOMs may disappear randomly from ADOM configuration while editing it.
639102 FortiAnalyzer may not apply Not equal to operator when Log Forwarding > Log Filter is configured with the GUI.
653371 CEF log forwarding start time does not match with event time.