Technical Tip: Different methods for migrating logs between FortiAnalyzer units
Description
This article describes the different methods that can be used to migrate logs between FortiAnalyzer units. The benefits and requirements of each method are compared.
This article can be useful in several scenarios, including hardware replacements or migration between platforms.
Scope
FortiAnalyzer.
Solution
The first two methods require both units to be up and running at the same time.
Log Aggregation (recommended approach if the old unit is still accessible):
This allows FortiGates to be repointed to the new FortiAnalyzer in real time and allows all the old logs to be added to the new logs being received on the new unit. Once all old logs have been aggregated to the new unit, the old unit can be decommissioned.
Technical Tip: Using log aggregation to migrate logs
Log Fetch:
In this method, the new unit requests the logs from the old unit and adds the logs to the logs it already has. Care must be taken to define the Fetch request of all ADOMs and for the full time range of logs that need to be migrated. This method might be preferred over Log Aggregation if only a portion of the logs on the old FortiAnalyzer are to be migrated.
Technical Tip: Using fetch requests to migrate logs
The next two methods require an external storage server, such as an FTP server, for saving archives, but do not require the old and new FortiAnalyzer to be up simultaneously.
Log Backup and Restore (recommended approach if the old unit is no longer accessible):
Restore will overwrite any logs already present, but it is accomplished in a single step.
Log Backup and Import:
Import will add logs to existing logs, but it must be performed one by one for each FortiGate. This is useful if the FortiAnalyzer to which logs are being migrated is already receiving logs from FortiGates.
Technical Tip: Using log backup and restore (or import) to migrate logs
