Skip to main content
Question

Missing Transferred Bytes/Traffic Size in FAZ to SOAR API Alerts

  • August 29, 2025
  • 8 replies
  • 68 views

MikelSA
Forum|alt.badge.img+8

Good morning,

At one of our clients we are sending alerts from FAZ to the SOAR via API. After reviewing the events/logs closely, I noticed that the fields related to transferred bytes or megabytes in the connections are not being included.

Is there any way to add these fields — perhaps through a configuration option or similar?

I saw the "Search logs" option under FAZ integration, but it doesn’t seem to be working.

Any ideas?

 

Thanks in advance.

8 replies

MikelSA
Forum|alt.badge.img+8
  • Author
  • Bronze 2
  • September 4, 2025

Any ideas? Thanks!


kentphelps
Staff
Forum|alt.badge.img+11
  • Staff
  • September 4, 2025

Are you using the FortiAnalyzer connector available on the SOAR Marketplace?

https://cloud.google.com/chronicle/docs/soar/marketplace-integrations/fortianalyzer


MikelSA
Forum|alt.badge.img+8
  • Author
  • Bronze 2
  • September 4, 2025

Are you using the FortiAnalyzer connector available on the SOAR Marketplace?

https://cloud.google.com/chronicle/docs/soar/marketplace-integrations/fortianalyzer

Yes i am, with the current actions available, but cant see the bytes


kentphelps
Staff
Forum|alt.badge.img+11
  • Staff
  • September 4, 2025

Are you trying to collect network traffic statistics?  I do not think the FortiAnalyzer connector supports that.  You might try with syslog & Bindplane: Collect Fortinet FortiAnalyzer logs


MikelSA
Forum|alt.badge.img+8
  • Author
  • Bronze 2
  • September 5, 2025

Are you trying to collect network traffic statistics?  I do not think the FortiAnalyzer connector supports that.  You might try with syslog & Bindplane: Collect Fortinet FortiAnalyzer logs

I tried the function “search logs” to collect any data that refers to the logs, but it shows me an error.

 


MikelSA
Forum|alt.badge.img+8
  • Author
  • Bronze 2
  • September 5, 2025

Error executing action FortiAnalyzer - Search Logs. Reason: An error occurred: Server error: Invalid tid 814812091 for fetching result.


kentphelps
Staff
Forum|alt.badge.img+11
  • Staff
  • September 5, 2025

You should open a support ticket to troubleshoot the Search Logs error


MikelSA
Forum|alt.badge.img+8
  • Author
  • Bronze 2
  • September 8, 2025

You should open a support ticket to troubleshoot the Search Logs error

Perfect thank you