Skip to main content
unknown1020
Explorer III
March 13, 2024
Solved

Total logs for analytics in FortiAnalyzer

  • March 13, 2024
  • 3 replies
  • 3482 views

Friends, a question, I have a fortianalyzer VM. I have several Fortigate devices synchronized with the FAZ for reporting purposes.

Previously, Total records for analysis were displayed: 60 days. Little by little it has been reducing and now I see Total logs for analytics: 20 days.

Could you help me by indicating what this is due to?

Screenshot_1.jpg

"Daily Log Limit Exceeded" alerts are also displayed.

Will this be related to the reduction of Total logs for analytics: 20 day?
I have 9 fortigates teams synchronized with the FAZ.

Screenshot_2.jpg

 

Best answer by ozkanaltas

 

Hello @unknown1020 ,

 

The answer to your first question is, this is about your storage area. You can set 60 days on configuration for Analytics but if your FortiAnalyzer doesn't have enough space on disk your analytics data keeps just up to your storage space. If you extend your log disk, FortiAnalyzer can keep analytics logs for more than 20 days. 

 

If you want to get information about how to extend log disk on FortiAnalyzer VM, you can review this document.

https://community.fortinet.com/t5/FortiAnalyzer/Technical-Tip-Extending-disk-space-in-FortiAnalyzer-VM/ta-p/194365

 

The answer to your second question is, that this is related to the daily quota for collecting logs. This is not related to the analytics log. This is about how much logs are processed daily. You can find more information about that in this link.

 

https://docs.fortinet.com/document/fortianalyzer-private-cloud/7.4.0/vmware-esxi-administration-guide/152093/about-fortianalyzer-on-vmware-esxi

3 replies

ozkanaltas
Valued Contributor III
March 13, 2024

 

Hello @unknown1020 ,

 

The answer to your first question is, this is about your storage area. You can set 60 days on configuration for Analytics but if your FortiAnalyzer doesn't have enough space on disk your analytics data keeps just up to your storage space. If you extend your log disk, FortiAnalyzer can keep analytics logs for more than 20 days. 

 

If you want to get information about how to extend log disk on FortiAnalyzer VM, you can review this document.

https://community.fortinet.com/t5/FortiAnalyzer/Technical-Tip-Extending-disk-space-in-FortiAnalyzer-VM/ta-p/194365

 

The answer to your second question is, that this is related to the daily quota for collecting logs. This is not related to the analytics log. This is about how much logs are processed daily. You can find more information about that in this link.

 

https://docs.fortinet.com/document/fortianalyzer-private-cloud/7.4.0/vmware-esxi-administration-guide/152093/about-fortianalyzer-on-vmware-esxi

unknown1020
Explorer III
March 14, 2024

thanks for the information.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!