FortiOS 7.6.7 – Significant increase in daily log volume sent to FortiAnalyzer without configuration changes
Hi,
after upgrading our FortiGate HA cluster from 7.4.12 to 7.6.7, we noticed a significant increase in the daily log volume sent to FortiAnalyzer.
Environment:
FortiGate: 2x FG-200F in HA
FortiOS: 7.6.7
FortiAnalyzer: VM, currently 8.0.0
Logging: FortiAnalyzer​
Before the upgrade, our daily log volume was normally below the licensed GB/day limit (15 GB). After the upgrade, the daily log rate increased by approximately 8–10 GB per business day, without any intentional configuration changes on the FortiGate side.
For a normal business day we now see approximately: Application Control log: ~10 GB/day, Traffic log: ~9 GB/day
​No firewall policies were intentionally changed, and we did not enable any additional logging options manually after the upgrade.
We have already checked the following:
-Â no known configuration change was made on the FortiGate before/after the upgrade
- application Control logging is enabled as before
- SSL inspection is enabled
- FortiAnalyzer is receiving logs correctly
- The increase is visible in FortiAnalyzer daily remote log volume statistics
We also tried creating custom FortiAnalyzer datasets to group logs by policyid/app/appcat, but the number of Application Control log entries does not seem extremely high, while the reported GB/day volume is very high. This makes us suspect either larger log payloads, changed log fields, or a change in how FortiAnalyzer calculates remote log volume after FortiOS/FAZ upgrade.
Is there any known change in FortiOS 7.6.7 that could increase the size or frequency of Application Control or Traffic logs sent to FortiAnalyzer?
Is there a recommended way on FortiAnalyzer to identify which policy ID, application, source IP, or log subtype is responsible for the increased log volume?
Can GenAI / AI application detection in FortiOS 7.6.x significantly increase App Control log size even if the number of log entries does not look extremely high?
Are there any recommended FortiGate or FortiAnalyzer CLI commands to compare log volume per policy / log type / application?
Any hints on how to troubleshoot this properly would be appreciated.
Thank you.
Jirka
