Troubleshooting Tip: How to fix a FortiAnalyzer that does not display analytic logs when logs are being inserted to the database
| Description | This article describes a case where the FortiAnalyzer is still receiving logs from a FortiGate, but the logs are not displayed in Analytics.
diagnose fortilogd msgrate
diagnose fortilogd lograte-device
Logs per second |
| Scope | FortiAnalyzer Virtual Machines. |
| Solution | To determine what causes the issue of analytic logs not appearing, check the kernel log.
If the following message exists: diagnose debug klog ...
diagnose system print partitions
SDB = 5.9TB virtual disk (5905580032 blocks) [Calculation 1K-block / 104876]. DM-0 = LVM logical volume using almost all of sdb (5905575936 blocks).
If the LVM logical volume is almost full, check the disk health in the Virtual Machine Environment disk health. This needs to be checked internally as the TAC scope only covers FortiAnalyzer OS and not the Virtual Machine platform.
If diagnose debug klog does not show any abnormal error, run the diagnose fsck harddisk to repair and check the disk. |
