Fortinet black logo

Known Issues

Known Issues

The following issues have been identified in FortiAnalyzer-BigData version 6.4.6. For inquires about a particular bug or to report a bug, please contact Fortinet Customer Service & Support.

LogView

Bug ID Description

718194

Archive logs are not stored properly and there is no ability to re-insert into analytic mode.

742679

In Log View log types takes a very long time to appear after upgrading from 6.2.5 to 6.4.6.

FortiView

Bug ID Description

742871

The link AntiVirus Check does not work for FortiSandbox Detection.

650965

FortiView can be slow sometimes.

736731

Exception is thrown in log when drill down to view Log View with filter Threat Name for Compromised Hosts.

736984

The Y-axis values are duplicate for Top Applications in second level.

742395

Exception is thrown in log when add filter Device ID to drill down for Compromised Hosts.

740738

There is no data displayed in bubble view for Top Threats (FortiClient).

742672

Exception is thrown in log when drill down to Log View with filter Risk for Top Cloud Applications.

Monitors

Bug ID

Description

722754

Exception in log is thrown for Top Endpoint Vulnerabilities (FortiClient) widget for Endpoints.

736728

The legend 0:0 should be removed for some widgets for Secure SD-WAN Monitor.

737477

The displayed time for X-axis is incorrect for Monitors > Archive > Security Fabric Score.

737492

There is no info displayed and no response in FAZ backend log for Top Endpoint Vulnerabilities widget.

738820

Could not resolve column/field reference: deviceip is thrown for Monitors > Endpoints > All Endpoints widget.

737547

Monitors: The security log count link is missing for the Log View details for WiFi >WiFi Clients widget.

740784

There is no data display for widget Best Practices Overview for Monitors > Fabric Sate of Security.

Reports

Bug ID Description

736960

All the predefined reports are missing in some custom ADOMs.

738253

The Time Period and Devices values are missing to display for most predefined reports.

739060

ParseException: Syntax error in line 1: is thrown in log when running datasets event-Wireless-Client-Details.

739054

Could not resolve column/field reference: total_app is thrown when running datasets saas-SaaS-Application-by-Session.

Common

Bug ID

Description

719810

Bigdata storage spacecannot be allocated by ADOMs.

727808

Data Ingestion, the blade 1 stopped receive and insert logs when disk usage is high, need to release disk automatically.

727944

FAZ CLI for ADOM quota setting cannot support 700+ adoms.

732066

Ingestion rate drop for a long time after powering off the master node.

737998

FAZ format disk CLI does not trigger BD side related operations, need to sync format disk behavior.

739588

Fabric log related outbreak services reports not fully supported yet in FortiAnalyzer Big Data.

741283

Retry mechanism needs to be added for FortiView and Report facet job.

741494

Facet job fails sometimes due to sql error Could not resolve column/field reference: 'dvid'\n.

742569

Currently does not support custom HTTPS port.

742630

IoC rescan, scanipc should add a process to handle the failed state if BD side returned err code.

742634

IoC rescan job's start and end time not correct.

Known Issues

The following issues have been identified in FortiAnalyzer-BigData version 6.4.6. For inquires about a particular bug or to report a bug, please contact Fortinet Customer Service & Support.

LogView

Bug ID Description

718194

Archive logs are not stored properly and there is no ability to re-insert into analytic mode.

742679

In Log View log types takes a very long time to appear after upgrading from 6.2.5 to 6.4.6.

FortiView

Bug ID Description

742871

The link AntiVirus Check does not work for FortiSandbox Detection.

650965

FortiView can be slow sometimes.

736731

Exception is thrown in log when drill down to view Log View with filter Threat Name for Compromised Hosts.

736984

The Y-axis values are duplicate for Top Applications in second level.

742395

Exception is thrown in log when add filter Device ID to drill down for Compromised Hosts.

740738

There is no data displayed in bubble view for Top Threats (FortiClient).

742672

Exception is thrown in log when drill down to Log View with filter Risk for Top Cloud Applications.

Monitors

Bug ID

Description

722754

Exception in log is thrown for Top Endpoint Vulnerabilities (FortiClient) widget for Endpoints.

736728

The legend 0:0 should be removed for some widgets for Secure SD-WAN Monitor.

737477

The displayed time for X-axis is incorrect for Monitors > Archive > Security Fabric Score.

737492

There is no info displayed and no response in FAZ backend log for Top Endpoint Vulnerabilities widget.

738820

Could not resolve column/field reference: deviceip is thrown for Monitors > Endpoints > All Endpoints widget.

737547

Monitors: The security log count link is missing for the Log View details for WiFi >WiFi Clients widget.

740784

There is no data display for widget Best Practices Overview for Monitors > Fabric Sate of Security.

Reports

Bug ID Description

736960

All the predefined reports are missing in some custom ADOMs.

738253

The Time Period and Devices values are missing to display for most predefined reports.

739060

ParseException: Syntax error in line 1: is thrown in log when running datasets event-Wireless-Client-Details.

739054

Could not resolve column/field reference: total_app is thrown when running datasets saas-SaaS-Application-by-Session.

Common

Bug ID

Description

719810

Bigdata storage spacecannot be allocated by ADOMs.

727808

Data Ingestion, the blade 1 stopped receive and insert logs when disk usage is high, need to release disk automatically.

727944

FAZ CLI for ADOM quota setting cannot support 700+ adoms.

732066

Ingestion rate drop for a long time after powering off the master node.

737998

FAZ format disk CLI does not trigger BD side related operations, need to sync format disk behavior.

739588

Fabric log related outbreak services reports not fully supported yet in FortiAnalyzer Big Data.

741283

Retry mechanism needs to be added for FortiView and Report facet job.

741494

Facet job fails sometimes due to sql error Could not resolve column/field reference: 'dvid'\n.

742569

Currently does not support custom HTTPS port.

742630

IoC rescan, scanipc should add a process to handle the failed state if BD side returned err code.

742634

IoC rescan job's start and end time not correct.