FortiManager & FortiAnalyzer
From Tech-Wiki
More actions
Operational FortiManager and FortiAnalyzer command reference covering device replacement, backups, task repair, logging, database rebuilds and alerting.
FortiManager device operations
Replace a failed device
The original procedure notes that the unregistered device should be deleted first.
Replace a device
execute device replace sn <device_name> <serial> execute fgfm reclaim-dev-tunnel
Restore FortiManager configuration
Restore all settings
execute migrate all-settings <ftp | scp | sftp> <server> <filepath> <user> <password> [cryptpasswd]
Enable scheduled scripts
config system admin setting
set show_schedule_script enable
endClear hit counters
Reset hit count
execute reset hitcount
Repair stuck tasks
Repair DVM tasks
diag dvm task repair
Debug policy push
Security Console debug
diag debug app securityconsole 255 diag debug enable
Disable verbose debug after collection
Verbose diagnostic output can be high-volume. Enable it only for the troubleshooting window and return the appliance to its normal diagnostic state afterwards.
FortiManager backup
config system backup all-settings
set status enable
set server "10.1.10.2"
set user "backup"
set directory "/home/backup/"
set week_days sunday
set time "23:00:00"
set passwd 1234
set crptpasswd 1234
endUse protected credentials
The values above are examples retained from the original article. Do not copy example passwords into a production backup configuration.
FortiGuard update status
Review update state and versions
diag autoupdate status diag autoupdate versions
FortiAnalyzer database operations
Rebuild the database index from log data:
Rebuild the local SQL database
exec sql-local rebuild-db diag sql status rebuild-db
FortiAnalyzer log rate
Display log/event rates
diag fortilogd lograte diag fortilogd msgrate-type
Archive logs
Back up all logs
execute backup logs all ftp|sftp|scp <server> <username> <password>
After archiving, the original procedure enables the configured log-retention/deletion setting under System Settings → File Management.
FortiGate syslog forwarding
config log syslogd setting
set status enable
set server 192.168.1.50
set reliable disable
set port 514
set csv disable
set facility alert
set source-ip 192.168.1.254
endLog-based email alerting
config system alert-event
edit warning
config alert-destination
edit 1
set type mail
set from [email protected]
set to [email protected]
set smtp-name mail.example.com
next
end
set enable-severity-filter enable
set severity-level-log error
set severity-level-comp =
set severity-filter medium
set event-time-period 1
set num-events 5
set enable-generic-text enable
set generic-text <string>
next
endRelevant values from the original reference:
severity-level-log:no-check,information,notify,warning,error,critical,alert,emergency.severity-level-comp:>=,=,<=.event-time-period:0.5,1,3,6,12,24,72,168.num-events:1,5,10,50,100.generic-textsupplies the string used for matching in generic-text/Grep mode.