Understanding FortiAnalyzer Fabric Topology:
The FortiAnalyzer Fabric topology is designed to centralize logging and analysis across multiple
devices in a network.
It involves a hierarchy where the supervisor node manages and coordinates with other Fabric
members.
Analyzing the Options:
Option A: Downstream collectors forwarding logs to Fabric members is not a typical configuration.
Instead, logs are usually centralized to the supervisor.
Option B: For effective management and log centralization, logging devices must be registered to the
supervisor. This ensures proper log collection and coordination.
Option C: The supervisor does not primarily use an API to store logs, incidents, and events locally.
Logs are stored directly in the FortiAnalyzer database.
Option D: For the Fabric topology to function correctly, all Fabric members need to be in analyzer
mode. This mode allows them to collect, analyze, and forward logs appropriately within the
topology.
Conclusion:
The correct statements regarding the FortiAnalyzer Fabric topology are that logging devices must be
registered to the supervisor and that Fabric members must be in analyzer mode.
Reference:
Fortinet Documentation on FortiAnalyzer Fabric Topology.
Best Practices for Configuring FortiAnalyzer in a Fabric Environment.