Archive issue
Ran into an incident where I need to do some digging into fortigate logs that were not being forwarded to FAZ. I was able to import the logs into FAZ, but I notice that a certain portion of the logs are not available for analytics, even though I have more than enough space for analytics allocated. The ADOM I put these logs into has 70GB storage, and I set it at 95% Analytics and 5% archive, as well as 365 days worth of analytics. Since this is temporary, i really dont need anything in archive. I imported about 4GB worth of logs, split across about 30 imported log files. For some reason, FAZ is putting 2.0GB of those logs in archive. What am I missing?