Technical Tip: FortiAnalyzer archive ADOM retention exceeding configured days due to log file time span
| Description | This article describes why ADOM archive retention in FortiAnalyzer may appear significantly higher than the configured value. |
| Scope | FortiAnalyzer. |
| Solution | In some cases, the ADOM archive retention may display values higher than the configured value (for example, 1741/365 days), even though the system is operating as expected.
This behaviour is due to how FortiAnalyzer calculates archive retention.
In the above example, the disk utilisation is configured as follows:
The value 1741/365 is calculated based on the existing archive logs. This can be seen in Log View -> Log Browse.
FortiAnalyzer determines the numbers based on the time range within the individual log files.
The retention value shown is calculated as: Current date to the earliest timestamp across the retained log files.
In the above example, the log file (e.g., .self) has logs from '2021', and this same file includes logs up to '2026'. Since this file contains recent logs within the configured 365-day retention period, it is not deleted.
The calculated retention becomes 'current date - earliest timestamp ≈ 1741 days'. If the extended retention is not required:
|



