Skip to main content
Connect your Fortinet FortiAnalyzer (FAZ) so Myrmex can search its log analytics, build entity dossiers, register FortiGate log sources, and check storage health. Myrmex reaches FortiAnalyzer over HTTPS (JSON-RPC at /jsonrpc) through a Collector on your network. Every search runs live, on demand — Myrmex queries the FAZ’s own log analytics and returns only what you ask for, copying or storing nothing on its side. Credentials are resolved on your side and never pass through the model.

What Myrmex Can Do

Log search with presets

Run FortiAnalyzer log searches live using analyst presets and return only the matching events.

Entity dossier

Enrich an IP, user, or host by pulling its activity from the FAZ on demand.

Register FortiGate sources

Register a FortiGate as a log source by serial number.

Storage & retention health

Check FortiAnalyzer storage and retention state to catch capacity issues early.

Before You Start

  • A Collector that can reach FortiAnalyzer over HTTPS (default port 443); the JSON-RPC endpoint is /jsonrpc. See Collector mode.
  • An admin whose profile has JSON API Access = Read-Write (CLI equivalent: under config system admin user, set rpc-permit read-write).
  • The ADOM you want Myrmex to work in (default root; per-call override is supported).

Step 1 — Create the Credential in FortiAnalyzer

1

Create an admin profile with JSON API access

In System Settings → Admin → Profiles, create or edit a profile and set JSON API Access to Read-Write.
2

Create the administrator

In System Settings → Admin → Administrators, add an admin, set a strong password, and assign the profile above.
3

Or configure it from the CLI

Equivalent CLI: under config system admin user, edit the account and run set rpc-permit read-write.
JSON API Read-Write is required because registering FortiGate log sources is a write action. Scope the admin profile to only the ADOMs Myrmex needs.

Step 2 — Add the Integration in Myrmex

From the Directory, choose Add Integration → FortiAnalyzer, then fill in:

Connect

Click Connect to validate the JSON-RPC connection and finish. FortiAnalyzer then appears under Environment → Integrations, and you can ask about it in the Workspace or through the Integration Specialist agent.
Registering a FortiGate as a log source is done by serial number. Have the device serial ready when you ask Myrmex to add a source.