Troubleshooting Tip: FortiGate losing logs or events after reboot
| Description | This article describes why FortiGate may be missing logs or events after every reboot and offers potential fixes. |
| Scope | Any supported version of FortiGate. |
| Solution | Logs and events can be stored directly on FortiGate in one of two places:
These can be configured in the GUI under Log & Report -> Log Settings:
When using FortiGate devices where disk logging cannot be enabled, it is recommended to use FortiAnalyzer or configure a syslog server to store real-time logs and events.
The command below is a key diagnostic command for investigating FortiGate instability, including scenarios where firewall logs are missing. It reveals process crashes, watchdog resets, or forced reboots, helping correlate system failures with interruptions in logging or network services.
Run the following in the FortiGate CLI:
diagnose debug crashlog read
Related articles: |




