Troubleshooting Tip: FortiAnalyzer disk reaches 100% due to FortiSIEM database
| Description | This article describes an issue where FortiAnalyzer disk utilization reaches 100% due to excessive growth of the SIEM database. This condition may cause system instability, log processing failure, and prevent firmware upgrades. |
| Scope | FortiAnalyzer: v7.4.10/v7.6.6. |
| Solution | Issue condition: The issue may be triggered or observed under the following conditions:
Symptoms:
Example disk usage output:
diagnose system print df -h
Filesystem Size Used Available Use% Mounted on
Solution/workaround: To disable the FortiSIEM module, the following CLI command can be used:
config system global
Note: Consider downtime, since the command below will require a reboot.
Resolution: This issue has been addressed in the following FortiAnalyzer versions:
|
