Use this command to:

  • restore the configuration or database from a file
  • change the FortiAnalyzer unit image
  • Restore device logs, DLP archives, and reports from specified servers.

This command will disconnect all sessions and restart the FortiAnalyzer unit.


execute restore all-settings {ftp | sftp} <ip:port> <filename> <username> <password> [<crptpasswd>] [option1+option2+...]

execute restore all-settings scp <ip> <filename> <username> <ssh-cert> [<crptpasswd>] [option1+option2+...]

execute restore image {ftp | scp | sftp} <filepath> <ip:port> <username> <password>

execute restore image tftp <string> <ip>

execute restore logs <device name(s)> {ftp | scp | sftp} <ip> <username> <password> <directory> [vdlist]

execute restore logs-only <device name(s)> {ftp | scp | sftp} <ip> <username> <password> <directory> [vdlist]

execute restore reports <report name(s)> {ftp | scp | sftp} <ip> <username> <password> <directory> [vdlist]

execute restore reports-config {<adom_name> | all]} {ftp | scp | sftp} <ip> <username> <password> <directory> [full]

Variable Description


Restore all FortiAnalyzersettings from a file on a FTP, SFTP, or SCP server. The new settings replace the existing settings, including administrator accounts and passwords.


Upload a firmware image from a(an) FTP/SCP/SFTP/TFTP server to the FortiAnalyzer unit. The FortiAnalyzer unit reboots, loading the new firmware.


Restore device logs and DLP archives from a specified server.


Restore device logs from a specified server.


Restore reports from a specified server.


Restore report configurations to a specified server.


Restore from an FTP server.


Restore from a SFTP server.


Restore from an SCP server.


Enter the IP address of the server to get the file from and optionally , for FTP servers, the port number.


Enter the server IP address.

<device names>

Device name or names, separated by commas, or all for all devices. Example: FWF40C3911000061

<report name(s)>

Restore specific reports (separated by commas), all for all reports, or reports with names containing given pattern.

A '?' matches any single character.

A '*' matches any string, including the empty string, e.g.:

  • foo: for exact match
  • *foo: for report names ending with foo
  • foo*: for report names starting with foo
  • *foo*: for report names containing foo substring.

{<adom_name> | all]}

Select to backup a specific ADOM or all ADOMs.


Enter the file to get from the server. You can enter a path with the filename, if required.


Enter the file path on the FTP server.


The username to log on to the server. This option is not available for restore operations from TFTP servers.


Enter the password, or - if there is no password.


Enter the SSH certificate used for user authentication on the SCP server.


Optional password to protect backup content. Use any for no password.


Enter keepbasic to retain IP and routing information on the original unit.


Enter the directory.


Reports configuration full restoration.


This example shows how to upload a configuration file from a FTP server to the FortiAnalyzer unit. The name of the configuration file on the FTP server is backupconfig. The IP address of the FTP server is The user is admin with a password of mypasword. The configuration file is located in the /usr/local/backups/ directory on the FTP server.

execute restore all-settings ftp /usr/local/backups/backupconfig admin mypasword