/jsonrpc) through a Collector on your network. Every search runs live, on demand — Myrmex queries the FAZ’s own log analytics and returns only what you ask for, copying or storing nothing on its side. Credentials are resolved on your side and never pass through the model.
What Myrmex Can Do
Log search with presets
Run FortiAnalyzer log searches live using analyst presets and return only the matching events.
Entity dossier
Enrich an IP, user, or host by pulling its activity from the FAZ on demand.
Register FortiGate sources
Register a FortiGate as a log source by serial number.
Storage & retention health
Check FortiAnalyzer storage and retention state to catch capacity issues early.
Before You Start
- A Collector that can reach FortiAnalyzer over HTTPS (default port
443); the JSON-RPC endpoint is/jsonrpc. See Collector mode. - An admin whose profile has JSON API Access = Read-Write (CLI equivalent: under
config system admin user,set rpc-permit read-write). - The ADOM you want Myrmex to work in (default
root; per-call override is supported).
Step 1 — Create the Credential in FortiAnalyzer
1
Create an admin profile with JSON API access
In System Settings → Admin → Profiles, create or edit a profile and set JSON API Access to Read-Write.
2
Create the administrator
In System Settings → Admin → Administrators, add an admin, set a strong password, and assign the profile above.
3
Or configure it from the CLI
Equivalent CLI: under
config system admin user, edit the account and run set rpc-permit read-write.Step 2 — Add the Integration in Myrmex
From the Directory, choose Add Integration → FortiAnalyzer, then fill in:Connect
Click Connect to validate the JSON-RPC connection and finish. FortiAnalyzer then appears under Environment → Integrations, and you can ask about it in the Workspace or through the Integration Specialist agent.Registering a FortiGate as a log source is done by serial number. Have the device serial ready when you ask Myrmex to add a source.