Fortinet black logo

Known Issues

Known Issues

The following issues have been identified in FortiAnalyzer version 6.4.3. For inquires about a particular bug or to report a bug, please contact Fortinet Customer Service & Support.

Device Manager

Bug ID

Description

639479 FortiGate v6.0 with sub-ca certificate cannot establish oftp connection to FortiAnalyzer without sub-ca certificate.

FortiView

Bug ID

Description

539298 Customer may not see data on cloud application bytes in FortiView.
579828 There may be bandwidth discrepancy under FortiView > Application & websites > Top websites.
616675 Bandwidth may not match between FortiAnalyzer and FortiGate.
616914 Some graphs may not render data in FortiView.
621453 ForiGate cannot get FortiClient's vulnerability detail information from FortiAnalyzer.
626530 Bytes Sent/Received should be matching between Top Destinations and Policy Hit charts under FortiView when filtered by the same policy ID.
633960 Filter is empty in request when drill-down Top Applications(FortiClient) view to Log View.
640553 FortiView monitor WiFi widget is not showing Bridged SSID information.
642837 If Sandbox detection supports only with FortiGate in Fabric ADOM, there should be an indication on GUI.
667076 FortiView Top Cloud Users may show no entry found message but there is a session graph shown.
668494 FortiView may not apply filter correctly for many of the entries.

673477

FortiView map fails to display traffic

667745

FortiView > Traffic > Top Sources may return zero value for time period less than four hours.

FortiSoC

Bug ID

Description

668942 With playbook running AV scan on endpoint may return error: "failed results- can not find parameters for connector".

Log View

Bug ID

Description

591272 Download Log files from Log View or browse are not in correct CSV format.
604850 The remote IP for SSL-VPN is showing as IPsec Remote IP.
625306 Hiding column(s) in Log View may cause filters to reference the incorrect column.
633393 Some of IPS archive files do not contain whole Attack Context but only contain BODY that is partial part of Attack Context.
635598 FortiAnalyzer may not display Traffic Logs in Log View and return Web Server Error 500.
638388 When two filters are defined and the first filter is removed, clicking on the remaining filer may reference the filter that was removed.
641013 After creating an ADOM for FortiMail, the ADOM is not visible in the GUI and mail domain logs are not going to the default FortiMail ADOM.
643858 Actual analytics logs does not match what is observed in log view.
652076 Log view may take a long time to load with Custom Time Period.
653765 Some log files under Log Browse may contain a mix of event and traffic messages.
661094 In Log View, importing alog may fail.
674027 Filtering FortiClient event logs with wildcard UID filter returns no data.

Others

Bug ID

Description

578907 exec log-aggregate all should aggregate all log files without any errors.
595696 The change of value for system.global.enc-algorithm is not applied to oftpd until a reboot.
621473 FortiSOC is missing in cloud-based VMs.
625343 FortiAnalyzer may consume high on I/O resources every hour by fazwatch.
632971 FortiAnalyzer should have the ability to query CPU utilization on individual CPU core.
660810 FortiAnalyzer-200F rebuild may get stuck and sqllogd may crash due to insufficient memory.
610161 FortiAnalyzer may unexpectedly set Don't Fragment flag with jumbo frame related packets in OFTP communications and in log forwarding.
665273 The diagnose system ntp status command may return error /bin/ntpq: read: Connection refused.

Reports

Bug ID Description
547496 FortiAnalyzer generates a report for selected device with outputs for all devices.
624911 FortiAnalyzer may not be able to generate the SaaS Application Usage Report with Obfuscate User feature.
628823 FortiAnalyzer is not generating all local Event logs for reports.
647868 After upgrade, all default reports and event handler list are lost.

System Settings

Bug ID Description
626636 The Allow button may now work in HA configuration page.
627683 The License Widget may not display the correct GB/day.
629663 Free text filter does not work when using (~) tilde sign on syslog ADOM for the msg field.
630654 Imported logs may not sync to slave.
634253 ADOMs may disappear randomly from ADOM configuration while editing it.
639102 FortiAnalyzer may not applying "Not equal to" operator when "Log Forwarding > Log Filter" is configured via GUI.
653371 CEF log forwarding start time does not match with event time.
660798 Device Log Settings > upload to FTP may not work correctly in collector-analyzer setup.
668067 NTPv3 enabled with authentication is not sending NTP client request with hardware platforms.
668901 After enabling Collector mode, FortiAnalyzer may not show FortiView.
672633 FortiAnalyzer HA primary unit may stop log insertion when there is postgres UPDATE on IOC.

Known Issues

The following issues have been identified in FortiAnalyzer version 6.4.3. For inquires about a particular bug or to report a bug, please contact Fortinet Customer Service & Support.

Device Manager

Bug ID

Description

639479 FortiGate v6.0 with sub-ca certificate cannot establish oftp connection to FortiAnalyzer without sub-ca certificate.

FortiView

Bug ID

Description

539298 Customer may not see data on cloud application bytes in FortiView.
579828 There may be bandwidth discrepancy under FortiView > Application & websites > Top websites.
616675 Bandwidth may not match between FortiAnalyzer and FortiGate.
616914 Some graphs may not render data in FortiView.
621453 ForiGate cannot get FortiClient's vulnerability detail information from FortiAnalyzer.
626530 Bytes Sent/Received should be matching between Top Destinations and Policy Hit charts under FortiView when filtered by the same policy ID.
633960 Filter is empty in request when drill-down Top Applications(FortiClient) view to Log View.
640553 FortiView monitor WiFi widget is not showing Bridged SSID information.
642837 If Sandbox detection supports only with FortiGate in Fabric ADOM, there should be an indication on GUI.
667076 FortiView Top Cloud Users may show no entry found message but there is a session graph shown.
668494 FortiView may not apply filter correctly for many of the entries.

673477

FortiView map fails to display traffic

667745

FortiView > Traffic > Top Sources may return zero value for time period less than four hours.

FortiSoC

Bug ID

Description

668942 With playbook running AV scan on endpoint may return error: "failed results- can not find parameters for connector".

Log View

Bug ID

Description

591272 Download Log files from Log View or browse are not in correct CSV format.
604850 The remote IP for SSL-VPN is showing as IPsec Remote IP.
625306 Hiding column(s) in Log View may cause filters to reference the incorrect column.
633393 Some of IPS archive files do not contain whole Attack Context but only contain BODY that is partial part of Attack Context.
635598 FortiAnalyzer may not display Traffic Logs in Log View and return Web Server Error 500.
638388 When two filters are defined and the first filter is removed, clicking on the remaining filer may reference the filter that was removed.
641013 After creating an ADOM for FortiMail, the ADOM is not visible in the GUI and mail domain logs are not going to the default FortiMail ADOM.
643858 Actual analytics logs does not match what is observed in log view.
652076 Log view may take a long time to load with Custom Time Period.
653765 Some log files under Log Browse may contain a mix of event and traffic messages.
661094 In Log View, importing alog may fail.
674027 Filtering FortiClient event logs with wildcard UID filter returns no data.

Others

Bug ID

Description

578907 exec log-aggregate all should aggregate all log files without any errors.
595696 The change of value for system.global.enc-algorithm is not applied to oftpd until a reboot.
621473 FortiSOC is missing in cloud-based VMs.
625343 FortiAnalyzer may consume high on I/O resources every hour by fazwatch.
632971 FortiAnalyzer should have the ability to query CPU utilization on individual CPU core.
660810 FortiAnalyzer-200F rebuild may get stuck and sqllogd may crash due to insufficient memory.
610161 FortiAnalyzer may unexpectedly set Don't Fragment flag with jumbo frame related packets in OFTP communications and in log forwarding.
665273 The diagnose system ntp status command may return error /bin/ntpq: read: Connection refused.

Reports

Bug ID Description
547496 FortiAnalyzer generates a report for selected device with outputs for all devices.
624911 FortiAnalyzer may not be able to generate the SaaS Application Usage Report with Obfuscate User feature.
628823 FortiAnalyzer is not generating all local Event logs for reports.
647868 After upgrade, all default reports and event handler list are lost.

System Settings

Bug ID Description
626636 The Allow button may now work in HA configuration page.
627683 The License Widget may not display the correct GB/day.
629663 Free text filter does not work when using (~) tilde sign on syslog ADOM for the msg field.
630654 Imported logs may not sync to slave.
634253 ADOMs may disappear randomly from ADOM configuration while editing it.
639102 FortiAnalyzer may not applying "Not equal to" operator when "Log Forwarding > Log Filter" is configured via GUI.
653371 CEF log forwarding start time does not match with event time.
660798 Device Log Settings > upload to FTP may not work correctly in collector-analyzer setup.
668067 NTPv3 enabled with authentication is not sending NTP client request with hardware platforms.
668901 After enabling Collector mode, FortiAnalyzer may not show FortiView.
672633 FortiAnalyzer HA primary unit may stop log insertion when there is postgres UPDATE on IOC.