FortiSIEM Archive Migration – Data Preservation with New IP (Mount Error)
Hello everyone,
We are currently working on a migration process for the Archive server in our FortiSIEM environment, and we would like to keep all existing archived data during this transition.
Our scenario is the following:
- The Archive server IP will be changed
- The goal is to reuse the existing storage and preserve all previously stored data
- The new Archive server is being configured to point to the same storage
However, when attempting to configure the Archive on the new server, we are receiving the following error:
Â
Archive test error: Data storage already mounted. Please provide a raw, unformatted and unmounted disk.
From our understanding, FortiSIEM expects a fresh disk during the Archive configuration process, but in our case, the disk already contains valid archive data that we need to maintain.
Questions:
- What is the correct procedure to migrate the Archive server while preserving existing data?
- Is there a supported way to attach an already-used disk without losing the stored events?
- Should the migration be done at the OS/storage level (e.g., NFS mount) instead of through the FortiSIEM interface?
- Are there any specific steps or documentation for this type of migration?
Any guidance or best practices would be greatly appreciated.
Thank you in advance!
