Fortinet black logo

Resolved Issues

Resolved Issues

The following issues have been fixed in FortiAnalyzer version 7.0.0. To inquire about a particular bug, please contact Customer Service & Support.

Device Manager

Bug ID

Description

521774 The Add and Delete function for unregistered devices are greyed out even when the root ADOM is locked.
523721 FortiAnalyzer should support FortiADC device type.
622649 When a FortiGate HA device is deleted, their log files are not deleted.

696853

When manually adding a device in FortiNAC ADOM, version v8.8 is not listed in the version option.

Fabric View

Bug ID

Description

554251 A user may not be able to see the fabric topology of devices in the user's assigned ADOM.

FortiSOC

Bug ID

Description

656293 FortiAnalyzer should automatically retrieve all software inventory after EMS connector is created.

FortiView

Bug ID Description
668494 FortiView may not apply filter correctly for many of the entries.
668922 Selecting FortiGate in FortiView Traffic logs returns Invalid params: Cannot find device XXX under adom XXX.
670844 Resources Usage Peak shows higher bandwidth than real usage.
671620 FortiAnalyzer SD-WAN View is not showing correct SLA output and cannot filter on specific SLA.
673477 FortiView map may fail to display traffic.
674461 Within FortiView VPN logs, the Country Flags may be incorrect.
678250 FortiView may show error when drill-down IOC rescan details.

682485

Policy hit count may be shown as zero while there is traffic.

682657 FortiView may not be refreshed correctly after switching between ADOMs.

684131

Top Sources response may be slow when filtering by Policy ID.

684193 Secure SD-WAN Monitor should not send a request when device list fails to load.

690895

FortiView > Monitors > Secure SD-WAN Monitor > SD-WAN Rules Utilization widget may show No Data for some FortiGates.

691570 FortiAnalyzer may not be able to cancel IOC re-scan task.
692464 FortiAnalyzer may prompt XSS erro while retrieving IPS error log details.
692852 After upgrade, the Secure SD-WAN Monitor may show No Data for Performance, Jitter, Latency, or Packet loss widget.
702268 Loading the FortiView page may be very slow when the Source is set as FortiAnalyzer when accessing it from FortiGate.

Log View

Bug ID

Description

522202 FortiAnalyzer may not able to accept syslog from FortiVoice.
591272 Downloaded Logs files from Log View or browse are not in the correct CSV format.
600083 Endpoint Identification should always show the same user tied to the same session.
625306 Hiding column(s) in Log view may cause filters to reference to incorrect column.
638388 When two filters are defined and the first filter is removed, clicking on the remaining filter may incorrectly reference a removed filter.
639228 FortiAnalyzer needs to synchronize FortiClient 6.4.1 new log format changes for Value of Type, Sub-type, and Event Type.
643858 Actual analytics logs do not match what is observed in log view.
652076 Log view may take a long time to load with Custom Time Period.
672350 FortiAnalyzer should able to view the space in between the user name on Log View > Event > VPN > User column.
672763 Level Column is empty on GUI when switching to Real-time Log on a FortiAnalyzer ADOM.

690922

The event logs filter should only display logs from its own VDOM.

Others

Bug ID Description
578907 The exec log-aggregate all should aggregate all log files without any error.
595696 The change of value for system.global.enc-algorithm is not applied to oftpd until a reboot.
610161 FortiAnalyzer may unexpectedly set Don't Fragment flag with jumbo frame related packets in OFTP communications and in log forwarding.
621473 FortiSOC is missing in cloud-based VMs.
653646 When formatting disk, database server may fail to shut down.

656370

FortiAnalyzer SCP backup cannot be stopped.

665273 The diagnose system ntp status command may return error /bin/ntpq: read: Connection refused.
666940 ADOM Mode Information has outdated wording about Reduced operation.
673224 The sqllogd may keep crashing after upgrading FAZ-3700F secondary unit.
675273 FortiAnalyzer to add SFTP and port support for all export commands.
675930 When calling an API, FortiAnalyzer may not update the progress with correct percentage.
676103 Webhook Fabric Connector sends the wrong Sever Name Indication (SNI) in the TLSv1.2 Client Hello.
677494 FortiAnalyzer may return SQL query error when creating temporary table blklst during ioc-rescan. Workaround: Please set ioc-rescan days to less than database compression days.
678200 FortiAnalyzer may stop inserting logs using high CPU usage.
681884 HA synchronization may stall at a random percentage.
682997 FortiAnalyzer may show fmgd crash during boot up after upgrade.

687809

Log insert lag time may go above 5 hours on a properly sized FortiAnalyzer.

693161 When frequently accessing different pages, FortiAnalyzer's GUI may become sluggish and pages may not transition.
696211 Secondary FortiAnalyzer accepts FTP connections after disabling FortiRecorder.
697654 FortiAnalyzer may return duplicated data within log view JSON response.
702140 The disable-module setting resets to default after reboot.

Reports

Bug ID

Description

547496 FortiAnalyzer generates a report for selected device with outputs for all devices.
624911 FortiAnalyzer may not be able to generate the SaaS Application Usage Reportwith Obfuscate User feature.
647868 After upgrade, all default reports and event handler list are lost.
662442 FortiAnalyzer should show report, template, chart library, and dataset under report section.
677060 Default Reports, Templates, Chart Library, Macro Library, or Datasets are missing on newly created ADOMs.
677109 Graphics may not be complete for FortiGate Performance Statistics Report.
695960 When accessing Throughout Utilization Billing Report, FortiAnalyzer may show a vertical line on the Interface Throughout Distribution chart when there is no interface data available.
704544 Application icons may not be displayed in report.

System Settings

Bug ID

Description

560895 FortiAnalyzer should separate the Admin profile setting for Log and SoC views.
580629 Chromebooks are unable to log to FortiAnalyzer if the admin has trusted hosts configured.
627683 The GB/day displayed in License Widget may not be correct.
631709 Email should be sent successfully from FortiAnalyzer with SMTPS TCP/465.
660798 Device Log Settings > Upload to FTP may not working correctly in collector-analyzer setup.
668067 NTPv3 enabled with authentication is not sending NTP client request with hardware platforms.
672633 FortiAnalyzer HA primary unit may stop log insertion when there is postgres UPDATE on IOC.
681321 Avatar may always synchronizing resulting in init sync cannot be finished.
681622 SMTP server password should not be limited to 63 characters.
689824 After upgrade, log filter setting may set to Equal to"for log forwarding.
691798 The secondary unit in FortiAnalyzer HA cluster may report HA cluster config-sync DOWN, cause=keepalive failure every couple of days.

708047

There may be multiple devid, devname, or tz columns when logs are forwarded in syslog.

Resolved Issues

The following issues have been fixed in FortiAnalyzer version 7.0.0. To inquire about a particular bug, please contact Customer Service & Support.

Device Manager

Bug ID

Description

521774 The Add and Delete function for unregistered devices are greyed out even when the root ADOM is locked.
523721 FortiAnalyzer should support FortiADC device type.
622649 When a FortiGate HA device is deleted, their log files are not deleted.

696853

When manually adding a device in FortiNAC ADOM, version v8.8 is not listed in the version option.

Fabric View

Bug ID

Description

554251 A user may not be able to see the fabric topology of devices in the user's assigned ADOM.

FortiSOC

Bug ID

Description

656293 FortiAnalyzer should automatically retrieve all software inventory after EMS connector is created.

FortiView

Bug ID Description
668494 FortiView may not apply filter correctly for many of the entries.
668922 Selecting FortiGate in FortiView Traffic logs returns Invalid params: Cannot find device XXX under adom XXX.
670844 Resources Usage Peak shows higher bandwidth than real usage.
671620 FortiAnalyzer SD-WAN View is not showing correct SLA output and cannot filter on specific SLA.
673477 FortiView map may fail to display traffic.
674461 Within FortiView VPN logs, the Country Flags may be incorrect.
678250 FortiView may show error when drill-down IOC rescan details.

682485

Policy hit count may be shown as zero while there is traffic.

682657 FortiView may not be refreshed correctly after switching between ADOMs.

684131

Top Sources response may be slow when filtering by Policy ID.

684193 Secure SD-WAN Monitor should not send a request when device list fails to load.

690895

FortiView > Monitors > Secure SD-WAN Monitor > SD-WAN Rules Utilization widget may show No Data for some FortiGates.

691570 FortiAnalyzer may not be able to cancel IOC re-scan task.
692464 FortiAnalyzer may prompt XSS erro while retrieving IPS error log details.
692852 After upgrade, the Secure SD-WAN Monitor may show No Data for Performance, Jitter, Latency, or Packet loss widget.
702268 Loading the FortiView page may be very slow when the Source is set as FortiAnalyzer when accessing it from FortiGate.

Log View

Bug ID

Description

522202 FortiAnalyzer may not able to accept syslog from FortiVoice.
591272 Downloaded Logs files from Log View or browse are not in the correct CSV format.
600083 Endpoint Identification should always show the same user tied to the same session.
625306 Hiding column(s) in Log view may cause filters to reference to incorrect column.
638388 When two filters are defined and the first filter is removed, clicking on the remaining filter may incorrectly reference a removed filter.
639228 FortiAnalyzer needs to synchronize FortiClient 6.4.1 new log format changes for Value of Type, Sub-type, and Event Type.
643858 Actual analytics logs do not match what is observed in log view.
652076 Log view may take a long time to load with Custom Time Period.
672350 FortiAnalyzer should able to view the space in between the user name on Log View > Event > VPN > User column.
672763 Level Column is empty on GUI when switching to Real-time Log on a FortiAnalyzer ADOM.

690922

The event logs filter should only display logs from its own VDOM.

Others

Bug ID Description
578907 The exec log-aggregate all should aggregate all log files without any error.
595696 The change of value for system.global.enc-algorithm is not applied to oftpd until a reboot.
610161 FortiAnalyzer may unexpectedly set Don't Fragment flag with jumbo frame related packets in OFTP communications and in log forwarding.
621473 FortiSOC is missing in cloud-based VMs.
653646 When formatting disk, database server may fail to shut down.

656370

FortiAnalyzer SCP backup cannot be stopped.

665273 The diagnose system ntp status command may return error /bin/ntpq: read: Connection refused.
666940 ADOM Mode Information has outdated wording about Reduced operation.
673224 The sqllogd may keep crashing after upgrading FAZ-3700F secondary unit.
675273 FortiAnalyzer to add SFTP and port support for all export commands.
675930 When calling an API, FortiAnalyzer may not update the progress with correct percentage.
676103 Webhook Fabric Connector sends the wrong Sever Name Indication (SNI) in the TLSv1.2 Client Hello.
677494 FortiAnalyzer may return SQL query error when creating temporary table blklst during ioc-rescan. Workaround: Please set ioc-rescan days to less than database compression days.
678200 FortiAnalyzer may stop inserting logs using high CPU usage.
681884 HA synchronization may stall at a random percentage.
682997 FortiAnalyzer may show fmgd crash during boot up after upgrade.

687809

Log insert lag time may go above 5 hours on a properly sized FortiAnalyzer.

693161 When frequently accessing different pages, FortiAnalyzer's GUI may become sluggish and pages may not transition.
696211 Secondary FortiAnalyzer accepts FTP connections after disabling FortiRecorder.
697654 FortiAnalyzer may return duplicated data within log view JSON response.
702140 The disable-module setting resets to default after reboot.

Reports

Bug ID

Description

547496 FortiAnalyzer generates a report for selected device with outputs for all devices.
624911 FortiAnalyzer may not be able to generate the SaaS Application Usage Reportwith Obfuscate User feature.
647868 After upgrade, all default reports and event handler list are lost.
662442 FortiAnalyzer should show report, template, chart library, and dataset under report section.
677060 Default Reports, Templates, Chart Library, Macro Library, or Datasets are missing on newly created ADOMs.
677109 Graphics may not be complete for FortiGate Performance Statistics Report.
695960 When accessing Throughout Utilization Billing Report, FortiAnalyzer may show a vertical line on the Interface Throughout Distribution chart when there is no interface data available.
704544 Application icons may not be displayed in report.

System Settings

Bug ID

Description

560895 FortiAnalyzer should separate the Admin profile setting for Log and SoC views.
580629 Chromebooks are unable to log to FortiAnalyzer if the admin has trusted hosts configured.
627683 The GB/day displayed in License Widget may not be correct.
631709 Email should be sent successfully from FortiAnalyzer with SMTPS TCP/465.
660798 Device Log Settings > Upload to FTP may not working correctly in collector-analyzer setup.
668067 NTPv3 enabled with authentication is not sending NTP client request with hardware platforms.
672633 FortiAnalyzer HA primary unit may stop log insertion when there is postgres UPDATE on IOC.
681321 Avatar may always synchronizing resulting in init sync cannot be finished.
681622 SMTP server password should not be limited to 63 characters.
689824 After upgrade, log filter setting may set to Equal to"for log forwarding.
691798 The secondary unit in FortiAnalyzer HA cluster may report HA cluster config-sync DOWN, cause=keepalive failure every couple of days.

708047

There may be multiple devid, devname, or tz columns when logs are forwarded in syslog.