Troubleshooting Tip: Disk Space utilization over 90% on the FortiGate
Description
This article describes how to troubleshoot HD usage from the partition.
Scope
FortiGate.
Solution
The total HD usage can be found by running the command 'diagnose sys logdisk usage'.
diagnose sys logdisk usage
Run the command below to verify the disk quota for logs:
diagnose sys logdisk quota
Run the following command:
fnsysctl df -h
Filesystem Size Used Available Use% Mounted on
none 7.1G 305.7M 6.8G 4% /tmp
none 7.1G 111.5M 7.0G 2% /dev/shm
none 7.1G 58.9M 7.1G 1% /dev/cmdb
/dev/sda1 231.9M 121.3M 97.7M 55% /data
/dev/sda2 1.6G 176.8M 1.3G 11% /data2
/dev/sdb1 29.4G 27.3G 577.0M 98% /var/log <- If Var/log/ is occupied more than 95%.
none 7.1G 58.9M 7.1G 1% /new_root/eap_proxy/dev/cmdb
/dev/sda1 231.9M 121.3M 97.7M 55% /new_root/eap_proxy/etc/cert/ca
/dev/sda1 231.9M 121.3M 97.7M 55% /new_root/eap_proxy_worker/etc/cert/ca
fnsysctl ls -l /var/log/log/root/
Check which logs are occupied under /var/log/. Some logs are old logs and if Archives are occupied, the Disk utilization will rise to 99% Before purging the log data, confirm a backup has been made via the TFTP server. If FortiAnalyzer is communicating with FortiGate, there is no need to take a backup:
To purge the log data, run the following command and enter the admin username and password when prompted.
It may take time for the hash prompt to appear as the purge task is running in the background, this can be verified with another putty session to review the directory: '/var/log' getting freed up by iterating the command a couple of times 'fnsysctl df -h'.
diagnose sys logdisk purge-log-data
Putty1:
FortidemoeFW # fnsysctl -dk -df -h
Filesystem Size Used Available Use% Mounted on
none 93.4G 1.3M 93.4G 0% /tmp
none 93.4G 1.1M 93.4G 0% /dev/shm
none 93.4G 300.0M 93.1G 0% /dev/cmdb
/dev/vda1 247.9M 93.1M 142.0M 40% /data
/dev/vda2 1.7G 58.0M 1.5G 3% /data2
/dev/vdb1 393.7G 138.2G 235.4G 37% /var/log
FortidemoeFW # diagnose sys logdisk purge-log-data
This operation will delete all disk logs and FortiView data stored in each virtual domain.
Only super admin users have permission to use this command!
Do you want to continue? (y/n)y
Admin: admin
Password:
FortidemoeFW #
FortidemoeFW #
===================================================
Putty2:
FortidemoeFW # fnsysctl df -kh
Filesystem Size Used Available Use% Mounted on
none 93.4G 1.3M 93.4G 0% /tmp
none 93.4G 1.1M 93.4G 0% /dev/shm
none 93.4G 300.0M 93.1G 0% /dev/cmdb
/dev/vda1 247.9M 93.1M 142.0M 40% /data
/dev/vda2 1.7G 58.0M 1.5G 3% /data2
/dev/vdb1 393.7G 87.4G 286.2G 23% /var/log
FortidemoeFW # fnsysctl df -kh
Filesystem Size Used Available Use% Mounted on
none 93.4G 1.3M 93.4G 0% /tmp
none 93.4G 1.1M 93.4G 0% /dev/shm
none 93.4G 300.0M 93.1G 0% /dev/cmdb
/dev/vda1 247.9M 93.1M 142.0M 40% /data
/dev/vda2 1.7G 58.0M 1.5G 3% /data2
/dev/vdb1 393.7G 83.9G 289.7G 22% /var/log
FortidemoeFW # fnsysctl df -kh
Filesystem Size Used Available Use% Mounted on
none 93.4G 1.3M 93.4G 0% /tmp
none 93.4G 1.1M 93.4G 0% /dev/shm
none 93.4G 300.0M 93.1G 0% /dev/cmdb
/dev/vda1 247.9M 93.1M 142.0M 40% /data
/dev/vda2 1.7G 58.0M 1.5G 3% /data2
/dev/vdb1 393.7G 78.2G 295.4G 21% /var/log
FortidemoeFW # fnsysctl df -kh
Filesystem Size Used Available Use% Mounted on
none 93.4G 1.3M 93.4G 0% /tmp
none 93.4G 1.1M 93.4G 0% /dev/shm
none 93.4G 300.0M 93.1G 0% /dev/cmdb
/dev/vda1 247.9M 93.1M 142.0M 40% /data
/dev/vda2 1.7G 58.0M 1.5G 3% /data2
/dev/vdb1 393.7G 61.0G 312.6G 16% /var/log
FortidemoeFW # fnsysctl df -kh
Filesystem Size Used Available Use% Mounted on
none 93.4G 1.3M 93.4G 0% /tmp
none 93.4G 1.1M 93.4G 0% /dev/shm
none 93.4G 300.0M 93.1G 0% /dev/cmdb
/dev/vda1 247.9M 93.1M 142.0M 40% /data
/dev/vda2 1.7G 58.0M 1.5G 3% /data2
/dev/vdb1 393.7G 58.5G 315.1G 16% /var/log
FortidemoeFW # fnsysctl df -kh
Filesystem Size Used Available Use% Mounted on
none 93.4G 1.3M 93.4G 0% /tmp
none 93.4G 1.1M 93.4G 0% /dev/shm
none 93.4G 300.0M 93.1G 0% /dev/cmdb
/dev/vda1 247.9M 93.1M 142.0M 40% /data
/dev/vda2 1.7G 58.0M 1.5G 3% /data2
/dev/vdb1 393.7G 54.3G 319.3G 15% /var/log
FortidemoeFW # fnsysctl df -kh
Filesystem Size Used Available Use% Mounted on
none 93.4G 1.3M 93.4G 0% /tmp
none 93.4G 1.1M 93.4G 0% /dev/shm
none 93.4G 300.0M 93.1G 0% /dev/cmdb
/dev/vda1 247.9M 93.1M 142.0M 40% /data
/dev/vda2 1.7G 58.0M 1.5G 3% /data2
/dev/vdb1 393.7G 49.6G 324.1G 13% /var/log
FortidemoeFW # fnsysctl df -kh
Filesystem Size Used Available Use% Mounted on
none 93.4G 1.3M 93.4G 0% /tmp
none 93.4G 1.1M 93.4G 0% /dev/shm
none 93.4G 300.0M 93.1G 0% /dev/cmdb
/dev/vda1 247.9M 93.1M 142.0M 40% /data
/dev/vda2 1.7G 58.0M 1.5G 3% /data2
/dev/vdb1 393.7G 33.5G 340.1G 9% /var/log
FortidemoeFW # fnsysctl df -kh
Filesystem Size Used Available Use% Mounted on
none 93.4G 1.3M 93.4G 0% /tmp
none 93.4G 1.1M 93.4G 0% /dev/shm
none 93.4G 300.0M 93.1G 0% /dev/cmdb
/dev/vda1 247.9M 93.1M 142.0M 40% /data
/dev/vda2 1.7G 58.0M 1.5G 3% /data2
/dev/vdb1 393.7G 32.2G 341.4G 9% /var/log
FortidemoeFW # fnsysctl df -kh
Filesystem Size Used Available Use% Mounted on
none 93.4G 1.3M 93.4G 0% /tmp
none 93.4G 1.1M 93.4G 0% /dev/shm
none 93.4G 300.0M 93.1G 0% /dev/cmdb
/dev/vda1 247.9M 93.1M 142.0M 40% /data
/dev/vda2 1.7G 58.0M 1.5G 3% /data2
/dev/vdb1 393.7G 20.8G 352.9G 6% /var/log
FortidemoeFW #
FortidemoeFW # fnsysctl df -kh
Filesystem Size Used Available Use% Mounted on
none 93.4G 1.3M 93.4G 0% /tmp
none 93.4G 1.1M 93.4G 0% /dev/shm
none 93.4G 300.0M 93.1G 0% /dev/cmdb
/dev/vda1 247.9M 93.1M 142.0M 40% /data
/dev/vda2 1.7G 58.0M 1.5G 3% /data2
/dev/vdb1 393.7G 9.9G 363.8G 3% /var/log
FortidemoeFW # fnsysctl df -kh
Filesystem Size Used Available Use% Mounted on
none 93.4G 1.3M 93.4G 0% /tmp
none 93.4G 1.1M 93.4G 0% /dev/shm
none 93.4G 300.0M 93.1G 0% /dev/cmdb
/dev/vda1 247.9M 93.1M 142.0M 40% /data
/dev/vda2 1.7G 58.0M 1.5G 3% /data2
/dev/vdb1 393.7G 7.3G 366.3G 2% /var/log
FortidemoeFW # fnsysctl df -kh
Filesystem Size Used Available Use% Mounted on
none 93.4G 1.3M 93.4G 0% /tmp
none 93.4G 1.1M 93.4G 0% /dev/shm
none 93.4G 300.0M 93.1G 0% /dev/cmdb
/dev/vda1 247.9M 93.1M 142.0M 40% /data
/dev/vda2 1.7G 58.0M 1.5G 3% /data2
/dev/vdb1 393.7G 4.0G 369.6G 1% /var/log
FortidemoeFW # fnsysctl df -kh
Filesystem Size Used Available Use% Mounted on
none 93.4G 1.3M 93.4G 0% /tmp
none 93.4G 1.4M 93.4G 0% /dev/shm
none 93.4G 300.0M 93.1G 0% /dev/cmdb
/dev/vda1 247.9M 93.1M 142.0M 40% /data
/dev/vda2 1.7G 58.0M 1.5G 3% /data2
/dev/vdb1 393.7G 1.0G 372.6G 0% /var/log
FortidemoeFW #
After finishing the purge:
Verify the disk size:
diagnose sys logdisk usage
fnsysctl df -h
fnsysctl ls -l /var/log/log/root/
The disk space will be reduced.
Note:
Super Admin privilege is required to run the 'fnsysctl' command. Otherwise, FortiGate will return an error as mentioned in this article: Technical Tip: fnsysctl command returns Unknown action 0
Related articles:
Troubleshooting Tip: How to clear short of flash space in FortiGate Disk partition
