EasyManua.ls Logo

Fortinet FortiAnalyzer 3.0 MR7 User Manual

Fortinet FortiAnalyzer 3.0 MR7
234 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
Page #1 background imageLoading...
Page #1 background image
www.fortinet.com
FortiAnalyzer
Version 3.0 MR7
ADMINISTRATION GUIDE

Table of Contents

Question and Answer IconNeed help?

Do you have a question about the Fortinet FortiAnalyzer 3.0 MR7 and is the answer not in the manual?

Fortinet FortiAnalyzer 3.0 MR7 Specifications

General IconGeneral
Version3.0 MR7
VendorFortinet
CategorySoftware
Log StorageCentralized log storage
FunctionLog management, analysis, and reporting
Supported DevicesFortiGate, FortiWiFi, FortiMail, FortiWeb, FortiManager, FortiAuthenticator, and virtual domains
ReportingCustom Reports
CompliancePCI, HIPAA
IntegrationFortiGate, FortiMail, FortiWeb

Summary

Introduction

About this document

Describes the document's purpose, scope, and chapters, including Fortinet documentation and support.

Fortinet documentation

Lists available FortiAnalyzer product documentation, including Administration Guide and CLI Reference.

Customer service and technical support

Provides information on accessing Fortinet Technical Support services and resources.

What’s new for 3.0 MR7

3.0 MR7 new features and changes

Details new features and changes in FortiAnalyzer 3.0 MR7, including dashboard and CLI enhancements.

Dashboard enhancements

Highlights new widgets added to the Dashboard and the ability to customize tabs.

Custom fields for log messages

Explains how to enable custom fields for log messages using the CLI for better indexing.

Alert email configuration changes

Describes changes in alert email configuration, including new required fields.

Administrative Domains (ADOMs)

About administrative domains (ADOMs)

Explains Administrative Domains (ADOMs) and their characteristics for constrained access.

Configuring ADOMs

Provides steps to enable, create, and manage ADOMs for segmented administration.

Assigning administrators to an ADOM

Details how to create administrators and assign them to specific ADOMs for access control.

System

Dashboard

Provides a summary of the FortiAnalyzer unit's status, including widgets and tabs.

Network

Covers network settings like interfaces, DNS, and routing.

Admin

Manages administrator accounts, access profiles, and authentication.

Config

Configures system features like logging, aggregation, IP aliases, and RAID.

Maintenance

Covers essential maintenance tasks like backup, restore, and firmware updates.

Device

Viewing the device list

Displays allowed devices, their connection permissions, and unregistered devices.

Manually adding a device

Provides steps to manually add devices to the FortiAnalyzer unit's list.

Blocking device connection attempts

Prevents specific devices from attempting connections to the FortiAnalyzer unit.

Configuring device groups

Organizes multiple devices into groups for simplified log browsing and reporting.

Log

Viewing log messages

Displays device and FortiAnalyzer logs in real-time or historical views.

Browsing log files

Allows viewing, downloading, or deleting stored log files for devices and the unit.

Customizing the log view

Enables display, arrangement, and filtering of log columns for detailed analysis.

Searching the logs

Provides methods for searching log files using Quick Search or Full Search.

Rolling and uploading logs

Controls log file size and consumption via rolling and scheduled uploads.

Content Archive

Viewing content archives

Displays archived content like HTTP web browsing and email messages.

Customizing the content archive view

Allows modification of content archive display by arranging columns and filtering.

Searching full email content archives

Enables quick searching of archived emails based on sender, recipient, or subject.

Reports

Configuring reports

Defines report layouts, schedules, data filters, and output templates.

Configuring report layout

Defines report structure, content, charts, and includes options for logos.

Configuring report schedules

Sets schedules for report generation, including frequency and time.

Configuring data filter templates

Creates templates to filter log information for specific report criteria.

Configuring report output templates

Creates templates for report output formats, email destinations, and FTP uploads.

Browsing reports

Allows viewing of all generated reports, including scheduled ones.

Quarantine

Viewing quarantined files

Displays a list of files quarantined by FortiGate units on the FortiAnalyzer hard disk.

Action

Options to delete, view details, or download quarantined files.

Alert

Alert Events

Defines log message criteria, severities, and sources that trigger administrator notifications.

Output

Configures how alert messages are sent via email, Syslog, or SNMP.

Configuring alerts by email server

Sets up the SMTP server for sending alert messages via email.

Configuring SNMP traps and alerts

Configures SNMP servers for receiving traps and sending alerts.

Configuring alerts by Syslog server

Configures Syslog servers to receive alert messages.

Network Analyzer

Connecting the FortiAnalyzer unit to analyze network traffic

Steps to connect the FortiAnalyzer to a switch's span port for traffic analysis.

Viewing Network Analyzer log messages

Displays real-time and historical traffic log messages captured by Network Analyzer.

Browsing Network Analyzer log files

Allows viewing, downloading, or deleting stored Network Analyzer log files.

Customizing the Network Analyzer log view

Enables display, arrangement, and filtering of Network Analyzer log columns.

Searching the Network Analyzer logs

Provides methods for searching traffic log files using Quick Search or Full Search.

Rolling and uploading Network Analyzer logs

Controls Network Analyzer log file size and consumption via rolling and uploads.

Tools

Preparing for the vulnerability scan job

Planning vulnerability scans, including target host preparation and credential setup.

Viewing vulnerability scan modules

Lists available remote vulnerability scan (RVS) modules and their severity levels.

Configuring vulnerability scan jobs

Creates and configures immediate or scheduled vulnerability scans.

Viewing vulnerability scan reports

Displays results of completed vulnerability scan jobs, including summaries and details.

File Explorer

Allows viewing and browsing of files stored on the FortiAnalyzer unit.

Managing firmware versions

Covers backing up, testing, upgrading, and reverting firmware on the unit.

Appendix: FortiAnalyzer reports in 3.0 MR7

FortiGate reports

Explains changes to FortiGate reports, including renamed or removed items.

Summary Reports

Summarizes changes in various report categories like Forensic and FortiMail.

FortiClient Reports

Lists FortiClient reports that remained unchanged after upgrading to FortiAnalyzer 3.0 MR7.

Related product manuals