Description |
The following article describes the potential causes of FortiAnalyzer's high lag-behind issue when logs are being sent from FortiAnalyzer to a syslog server. |
Scope |
FortiAnalyzer sends logs to a syslog server. |
Solution |
Behavior and Symptoms:
diag test app logfwd 4 ** Loader: <name of syslog server> lag-behind=99.95%
Conclusion: The rate of sending logs from FortiAnalyzer to the syslog server was high , which seemed to overwhelm the syslog server, adjusting settings on the syslog server can help in fixing the issue.
Furthermore, the RTT delay between FortiAnalyzer and the Syslog server can impact the number of logs sent over TCP. |
Labels: