Skip to main content
ymasaki
Staff
Staff
September 3, 2024

Technical Tip: FortiEDR Log Retention Periods

  • September 3, 2024
  • 0 replies
  • 2342 views
Description This article describes the log retention periods to ensure how long different types of logs are retained within the system.
Scope FortiEDR.
Solution

FortiEDR categorizes logs into four distinct types each with its own specified retention period:

Log type Description Location Retention Period
Security Events Incidents and alerts related to potential security threats and anomalies detected by FortiEDR Collector. Event Viewer At least 1 year
System Events System related activities in the FortiEDR system. ADMINISTRATION -> SYSTEM EVENTS 9-10 months (200 days)
Audit Trail User related actions in the FortiEDR system. TOOLS -> AUDIT TRAIL 9-10 months (200 days)
Threat Hunting Endpoint activities including Process, File, Network, Registry and Log actions. - THREAT HUNTING in v6.2
- FORENSICS -> Threat Hunting in v6.0 or below
*Approx. 30 days with the default Inventory Profile

 

Visit How to Maximize data retention for Threat Hunting Repository for more information about the Threat Hunting log retention.

 

If the retention periods do not meet the organization's compliance, FortiEDR provides the option to forward logs to an external Syslog server. This setup allows for extended storage and backup of critical logs.

For syslog setup, visit the admin guide Syslog.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.