Skip to main content
AlexFerenX
Visitor III
June 17, 2024
Question

Show "Log Storage Policy" using CLI?

  • June 17, 2024
  • 9 replies
  • 2507 views

Hi!

whilst configured parameter of "Log Storage Policy" are seen using "diagnose log device", is there a CLI command to show "Actual Logs for X Days" I see in GUI?

Also.. is there a command to show values seen "Analytics Storage Statistics" (when one clicks "Analytics Policy" and graphs in "Log Storage Policy" ?

R's, Alex

9 replies

amuda
Staff
Staff
June 19, 2024

Dear @AlexFerenX ,

 

You may refer here: Displaying logs via FortiGate's CLI - Fortinet Community

 

srajeswaran
Staff
Staff
June 19, 2024

Please try "diagnose test application logfiled 4 <ADOM Name> "

diagnose test application logfiled 4 ALL -> to see all ADOM statistics.

Below given are the additional options available.

# diagnose test application logfiled

Logfile Daemon Test Usage:
1: Daemon info (PID, meminfo, backtrace ...)
2: show statistics and state
4: show ADOM statistics ([adom-filter(adom-name or 'ALL' or oid in format of 'oid=123') [force-refresh | dev-filter|* [vd-filter|*]])
5: show device statistics ([devid-filter [vd-filter|*]])
6: show auto-del statistics
7: show log file disk usage ([dev-filter|* [vd-filter|*])
8: update, show log file disk usage ([devid [vd [from-ndays-ago [to-ndays-ago ]]])
9: show inode usage
10: enable or diable debug filter of device and vdom
11: du cache diag commands
12: force to check the oldest log litime when trim log files.
13: force to delete log files older than <days> to enforce deletion policy for uploaded log files (<days>).
90: reset statistics and state
91: force to preen content files info
99: restart daemon

AlexFerenX
Visitor III
June 20, 2024

Thank you, @srajeswaran 

Using argument "4", I see "db=XXX days(actual from ...." and this seems to coincide with Analytics 'Actual Logs for XXX Days' in GUI's Log Storage Policy, however, is there an equivalent for Archive Log?

R's, Alex

srajeswaran
Staff
Staff
June 20, 2024

"db" refers to "Analytics Logs" and "log" refers to "Archive Logs". So as per below output Analytics logs are assigned with 700MB (70%) , Archive logs are with 300.0MB quota.
Archive logs are configured to keep logs for 365 days and Analytics logs for 60 days, you can also see the actual usage from date and to date on same output, my device don't have any logs.

quota : 1000.0MB(log=300.0MB, db=700.0MB), split_ratio=70%(db), trim_thres=90%
retention : log=365 days, db=60 days(no data), last_chk=7h56m32s(ago) next_chk=4h3m28s(later)

You can also use "diagnose log device" to get details per device.

Thought Leadership. Security Summit. Thursday, November 12th, PGA National Resort, Palm Beach Gardens, FL.
Thought Leadership. Security Summit. Thursday, October 8th. Disney's Grand Californian Hotel & SPA, Anaheim, CA.