Skip to main content
DanieleS99
Explorer
February 4, 2022
Question

Fortigate Storage and log best practices

  • February 4, 2022
  • 2 replies
  • 5892 views

Hi,

I try to understand what do these data refer to, the fortigate or the fortianalyzer?

Cattura3.JPG
I also wanted to understand what could be the correct solutions to make sure that it does not reach 100%, such as putting retention to the logs... I just don't understand exactly where I have to act and how.
I would still like to keep the logs on both the fortigate and the fortianalyzer.
Clearly I couldn't find much documentation about it...

Thanks

2 replies

AlexC-FTNT
Staff
Staff
February 4, 2022

These refer to the logs in FortiGate disk.

Don't be afraid to use the "?" when running commands - it will show you what you can configure. I think you are looking for these settings:

AlexCFTNT_0-1643988278448.png

 

DanieleS99
Explorer
February 4, 2022

Unlickily in version 7.0.3 of Fortigate I don't see the "disk" setting when I do the command "config log"...

Thanks

AlexC-FTNT
Staff
Staff
February 4, 2022

make sure the disk is present (get sys status >> Log Hard Disk). You may see "need format". Plus not all units have disk. 
The command did not change in 7.0.3:

AlexCFTNT_0-1643989393118.pngAlexCFTNT_1-1643989449796.png

 

DanieleS99
Explorer
February 4, 2022

you are right, I see Log Hard disk: not available