Known Issues
The following issues have been identified in FortiAnalyzer version 7.2.4. To inquire about a particular bug or to report a bug, please contact Fortinet Customer Service & Support.
Device Manager
| Bug ID | Description |
|---|---|
|
861979 |
FortiAnalyzer generates "Invalid user/password for Security Fabric device in Device manager" even though the password is correct. |
| 888797 | The ip address is not updated on FortiAnalyzer when the FortiGate is forwarded from Collector mode FortiAnalyzer. |
|
927113 |
FortiAnalyzer displays incorrect EMS server version, IP address, and connectivity status. |
| 927747 | Connectivity status of FortiMail/FortiClient EMS shows the status "Unknown". |
| 937850 | Device Connectivity status is displayed as "Unknown" under Device Manager. |
| 956536 | Unable to add FortiNAC device to FortiAnalyzer. |
|
986754 |
The connectivity status of devices is displayed as "Unknown", while other fields are "N/A". |
| 1106056 | Deleting a model device may result in the removal of the Logs folder under Storage. This issue occurs only if the model device never comes online and does not match a FortiGate. |
Fabric View
| Bug ID | Description |
|---|---|
| 918006 | An issue with the EMS Asset Inventory has been identified. When running the playbook, no assets or inventory are displayed on FortiAnalyzer, and the Fabric View lists remain empty. |
FortiSOC
| Bug ID | Description |
|---|---|
| 959875 | In the Playbook Monitor, the status of the default playbook "Update Asset and Identity Database" is displayed as failed. |
FortiView
| Bug ID | Description |
|---|---|
| 783408 | When selecting 'IPSec VPN'
login type under the Top Failed Authentication tab, it displays No Results. |
| 914972 | Unable to view detailed logs about the Compromised Host. |
| 946188 | Unable to get more details about the Compromised Hosts in FortiView. |
| 954542 | When the time range is extensive, FortiAnalyzer may experience limitations in handling data points, resulting in potential omissions of data entries in the final results for FortiView SD-WAN Monitors widgets. |
| 954773 | Top Threat Destinations widget doesn't show expected data according to selected TOP Numbers. |
| 984498 | The device drop-down list on the SD-WAN summary under FortiView displays "failed loading data". |
Log View
| Bug ID | Description |
|---|---|
| 775185 | Duplicated logs have the potential to adversely impact the overall performance of the FortiAnalyzer. |
| 937729 |
Log View > Fabric filter does not work with classless subnets. |
|
941273 |
When selecting a log attribute for filtering, no value options are provided. |
| 962540 |
Log View page does not loadwhen log filters are applied. Workaround: Refresh the page. |
| 974762 | The horizontal scroll bar is missing from the detailed information window for events in Log View. |
Others
| Bug ID | Description |
|---|---|
|
812931 |
VIP access is not supported due to the new Azure API changes in HA VRRP. |
| 893699 | Login failed for restapi request due to invalid user/password. |
| 914320 | There are multiple harmful errors displayed on the console's output during the software upgrade process to 7.2.4. These errors might be related to "FGT-siem" which is removed from v7.2.3 and v7.4, but it still exists in v7.2.2 and below, v7.0, and v6.4. |
| 924123 | FortiAnalyzer-1000Fdoes not support FortiWeb-1000F. |
|
925250 |
The sqlreportd process may consume excessive resources on the FortiAnalyzer when retrieving logs from multiple FortiGate ("more than 100 FortiGates") at the same time. Consequently, users may experience some performance slowdowns. |
|
933475 |
logs of ha secondary are not visiblewhen the ha is a csf's member. |
|
950501 |
The "execmd" process entering the Zombie state causes temporary slowdown and unresponsiveness in the FortiAnalyzer GUI. |
|
951791 |
Continuous crashes for the "file parsed Application" on FAZ HA have been observed. |
| 952295 | FortiAnalyzer does not remove the logs after forwarding then to the cloud storage. |
| 965803 | Due to some Redis-related issues, the "diagnose
log device" command displays "Information Not Available" for all ADOMs, and
newly generated reports are not visible on the GUI. |
| 1035217 |
When "ADOM Mode" is set to "Advanced", if users remove one VDOM from non-root ADOM, the entire FortiGate device with all of the its VDOMs might be removed from FortiAnalyzer. |
Reports
| Bug ID | Description |
|---|---|
|
936084 |
No data is shown in report when filter applied to chart in FortiMail ADOM. |
|
952229 |
Certain charts in the reports are not employing consistent session counting logic within the base hcache for FGT_DATASET_BASE_TRAFFIC_BANDWIDTH_SESSION. This inconsistency might result in inaccurate results. |
Services
| Bug ID | Description |
|---|---|
|
985074 |
Changing the FortiGuard Server Location under the license info widget results in a blank page popup. |
System Settings
| Bug ID | Description |
|---|---|
| 832265 | Enabling exclusions for log forwarding results in empty fields in the Exclusion List. |
| 898944 | When the ADOM name is changed, it does not update under the 'Log Forward' in the 'Select Device Filter'. |
| 927773 | When specific ADOMs are selected as Filters, Log Forwarding stops to function. |
| 934625 | Adding devices to "Log-forward filter" creates duplicates of previously added devices. |
|
941261 |
Users can't access the "Log Forwarding" section; it displays a "Failed to load" error message. |
| 953842 | Log Forwarding does not filter logs based on the specific ADOMs. |
|
956884 |
FortiAnalyzer's HA Status consistently switches to "Negotiating" during the process of HA configuration synchronization. |