Skip to main content
ddsouza_FTNT
Staff
Staff
February 11, 2022

Technical Tip: How to collect the logs needed for investigating logdisk usage and log related problems

  • February 11, 2022
  • 0 replies
  • 3237 views

Description

This article describes steps to collect the logs needed for investigating the high log disk usage and log-related problems.

Scope

FortiWeb version 6.0 and above.

Solution

For Logdisk usage: Log in to FortiWeb SSH by using the default 'admin' account and collect the output of the following commands (make sure to record the SSH session output to a file).

get system status
get log disk
get log traffic-log

diagnose system mount list
diagnose debug crashlog show
diagnose hardware harddisk list
diagnose hardware logdisk info
diagnose index all show

fn ls -la /var/log
fn ls -la /var/log/fwlog/root/disklog/
fn ls -la /var/log/fwlog/root/database/
fn du -scH /var/log/
fn du -aH /var/log/
fn du -scH /var/log/fwlog
fn du -aH /var/log/fwlog
fn du -scH /var/log/fwlog/root/disklog/
fn du -aH /var/log/fwlog/root/disklog/
fn du -scH /var/log/fwlog/root/database/
fn du -aH /var/log/fwlog/root/database/
fn du -scH /var/log/fwlog/root
fn du -aH /var/log/fwlog/root


For Traffic/attack/event logs related problems: 

Log in to FortiWeb SSH and run the following debug commands. (Make sure to record the SSH session output to a file.)

diagnose deb reset
diagnose debug application logd 7
diagnose debug enable


Reproduce the problem and wait for two minutes. 

Then, turn off debugging by running the following commands.

diagnose debug disable 


Log in to FortiWeb SSH using the default 'admin' and run the following debug commands.
(Make sure to record the SSH session output to a file.)

fn cat /var/log/dlog_indexd
fn cat /var/log/dlog_logd
fn cat /var/log/mysql/error.log
fn cat /proc/miglog/alog/brief
fn cat /proc/miglog/tlog/brief
fn cat /proc/miglog/elog/brief

 

Wait for 2 minutes, then execute the following commands.

fn cat /proc/miglog/alog/brief
fn cat /proc/miglog/tlog/brief
fn cat /proc/miglog/elog/brief

 

As the 'logs not showing up problem' could be the byproduct of a high logdisk usage problem, collect the output of the commands mentioned above in the 'For Logdisk usage'.

  • Along with the above files, attach the configuration backup and the system debug file.


To download the system debug file, go to System -> Maintenance -> Debug -> Debug Log and Download the debug log file (refer to the screenshot added below).

 

ddsouza_FTNT_0-1644561803597.png

 

  • Download the Event logs from Log&Report -> Log Access -> Download.

  • Attach all of the files to the ticket.

Related article:
Technical Tip: How to identify and troubleshoot a hard disk/log disk failure with FortiWeb

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!