FortiView from FortiAnalyzer
Attaching a FortiAnalyzer to the FortiGate increases the functionality of FortiView. For example, it adds the Compromised Hosts view.
The following devices are required:
- A FortiGate or FortiOS
- A compatible FortiAnalyzer (see https://docs.fortinet.com/document/fortianalyzer/6.2.0/compatibility-with-fortios)
To enable FortiView from FortiAnalyzer:
- On the FortiGate, go to Security Fabric > Settings.
- Turn on FortiAnalyzer Logging and enter the IP address of the FortiAnalyzer device.
- Click Test Connectivity. A message will be shown stating that the FortiGate is not authorized on the FortiAnalyzer.
- On the FortiAnalyzer, go to Device Manager.
- In the device list, right click the just added FortiGate, then click Authorize.
- On the FortiGate, go to Security Fabric > Settings and click Test Connectivity to confirm that the device is now authorized.
- Go to FortiView > Sources.
- Select a time range other than now from the drop-down list to view historical data.
- From the source drop-down list, select FortiAnalyzer.
All the historical information now comes from the FortiAnalyzer.