Troubleshooting Tip: How to check a slow FortiAnalyzer Virtual Machine
Description
This article describes how to handle a specific problem with a slow FortiAnalyzer on a Virtual Machine environment.
Scope
FortiAnalyzer, general.
Solution
If FortiAnalyzer is slow, carry out a performance check to see if the VM is not installed on a heavily loaded hypervisor.
diagnose system klog
Note: Kernel logs show low-level system messages generated by the underlying OS kernel.
If the following is seen in the previous logs, consider the advice below:
<4>[104725.045794] hrtimer: interrupt took 7981185 ns
This indicates that the FortiAnalyzer VM is installed on a heavily loaded hypervisor, commonly on Hyper-V.
This applies to every virtual environment platform, however.
To fix this, try to move the FortiAnalyzer VM to another hypervisor. Remember that the FortiAnalyzer is a solution that requires high-priority resources to operate correctly.
Important note:
If high iowait times are shown, the possible cause of the problem can be that the communication between the hypervisor and the local storage.
get system performance CPU: Used: 54.22% Used(Excluded NICE): 54.22% %used %user %nice %sys %idle %iowait %irq %softirq CPU0 26.60 0.19 0.00 0.39 73.40 25.83 0.00 0.19 CPU1 64.15 3.29 0.00 4.26 35.85 56.59 0.00 0.00 CPU2 57.93 0.59 0.00 1.17 42.07 56.16 0.00 0.00 CPU3 34.17 0.97 0.00 1.17 65.83 31.65 0.00 0.39 CPU4 57.59 0.39 0.00 0.78 42.41 56.42 0.00 0.00 CPU5 69.79 0.39 0.00 1.17 30.21 68.23 0.00 0.00
Related articles:
Technical Tip: How to gather information and fix high CPU and memory utilization conditions
Troubleshooting Tip: Deep FortiAnalyzer performance troubleshooting
Technical Tip: How to improve FortiAnalyzer performances when FortiSIEM module is not needed
