Skip to main content
FMG_TAC_Eng_1
Staff
Staff
August 22, 2021

Technical Tip: Log data migration limitations between two FortiAnalyzer virtual machines

  • August 22, 2021
  • 0 replies
  • 2086 views

Description

This article describes the consequences of improper disk migration on FortiAnalyzer VMs.

FortiAnalyzer VM, in current releases, uses Local Volume Manager (LVM) libraries to map and control block storage devices attached to a virtual machine. From a system administrator point of view, this allows an easy storage extension.

Scope

FortiAnalyzer VM.

Solution

When a FortiAnalyzer VM is launched for the first time, the system will be started from a virtual disk which is included in the downloaded image from the support portal, and the second data drive will be prepared on the initial start by creating an LVM structure on the disk and formatting the volume to the ext4 filesystem.

kb_20584_1.png


After configuring FortiAnalyzer logging on the FortiGate and authorizing the firewall on the FortiAnalyzer, log data and files on the storage disk are visible, as shown below:
 

kb_20584_2.png

 
How not to migrate data between two FortiAnalyzer VMs:

If another VM is created and attached to an existing storage disk to the new FortiAnalyzer, all log data will be deleted, and no FortiView or Reports will be left.

 

kb_20584_3.png


If it is compared after the migration, the /Storage folder contains less data than it had originally.  
 

kb_20584_4.png


Related articles:

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.