Skip to main content
chall_FTNT
Staff
Staff
July 16, 2026

Technical Tip: Using fetch requests to migrate logs

  • July 16, 2026
  • 0 replies
  • 113 views

Description


This article describes how to use Fetch Requests to Migrate Logs between 2 FortiAnalyzer units.


This could be used to run reports on another FortiAnalyzer based upon archive logs. Or as a potentially more selective method of migrating logs over to a new deployment.

Scope


FortiAnalyzer.

Solution


The fetching function is only available if the old FortiAnalyzer instance is still reachable and operational.

Set up a fetch_account on the old FortiAnalyzer:

config system admin user
    edit "fetchadmin"
        set password password
        set profileid "Super_User
        set adom "all_adoms"


Configuration of the Fetch request on the new FortiAnalyzer:

Fetcher Management:

kb_11815_7.png


Create a Profile:

kb_11815_8.png


Fetcher Request:

kb_11815_9.png


Accept the fetching request on the old FortiAnalyzer:

kb_11815_11.png


kb_11815_12.png


One advantage of log fetching is the ability to filter out unwanted logs based on time.
However, if multiple ADOMs are present, fetching must be configured for each individual.

Debug commands:

execute tac report
diagnose debug app log-fetch 8
diagnose debug enable


Launching the fetching and recording the output on both the sender and receiver:

diagnose test application log-fetch
diagnose test application log-fetch 2
diagnose test application log-fetch 3


diagnose test application log-fetch -> It will display the possible options.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!