Skip to main content
jjdope
Staff
Staff
April 6, 2026

Technical Tip: FortiAnalyzer archive ADOM retention exceeding configured days due to log file time span

  • April 6, 2026
  • 0 replies
  • 174 views
Description This article describes why ADOM archive retention in FortiAnalyzer may appear significantly higher than the configured value.
Scope FortiAnalyzer.
Solution

In some cases, the ADOM archive retention may display values higher than the configured value (for example, 1741/365 days), even though the system is operating as expected.

 

This behaviour is due to how FortiAnalyzer calculates archive retention.

 

1.png

 

In the above example, the disk utilisation is configured as follows:

 

1.png

 

The value 1741/365 is calculated based on the existing archive logs. This can be seen in Log View -> Log Browse.

 

1.png

 

FortiAnalyzer determines the numbers based on the time range within the individual log files.

  • The earliest ('From') timestamp. 
  • The latest ('To') timestamp.

 

The retention value shown is calculated as:

Current date to the earliest timestamp across the retained log files.

 

In the above example, the log file (e.g., .self) has logs from '2021', and this same file includes logs up to '2026'.

Since this file contains recent logs within the configured 365-day retention period, it is not deleted.

 

The calculated retention becomes 'current date - earliest timestamp â‰ˆ 1741 days'.

Workaround:

If the extended retention is not required:

  1. Navigate to 'Log View -> Log Browse'.
  2. Identify log files with very old 'From' timestamps and manually delete those files.
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!