Description | This article describes running a custom report on firewalls entering conserve mode on FortiAnalyzer using a custom Dataset. |
Scope | Any supported version of FortiAnalyzer. |
Solution |
Make sure to receive the logs on the FortiAnalyzer so that it can be used to generate reports.
Related article: Troubleshooting Tip: FortiGate to FortiAnalyzer connectivity
Log example for conserve mode:
date="2023-11-22" time="01:03:39" id=7304054965926890395 bid=16466602 dvid=1782 itime=1700607819 euid=3 epid=3 dsteuid=3 dstepid=3 logver=702051517 logid="0100022011" type="event" subtype="system" level="critical" msg="Kernel enters memory conserve mode" logdesc="Memory conserve mode entered" conserve="on" red="1642 MB" green="1530 MB" total=1866 used=1644 service="kernel" eventtime=1700607817932994002 tz="+0200" devid="FGVM02TM22000806" vd="root" devname="Lab-1"
Create a new Dataset using the below Query:
"select vd, devname, devid, msg, count(*) as Number from $log
If the message is 'Kernel enters extreme low memory mode' , create a new Dataset using the below Query :
"select vd, devname, devid, msg, count(*) as Number from $log
Create a new Chart, using the 'Conserve mode' Dataset :
Create a new Report :
On the tab Editor, insert Chart using the 'Conserve mode' :
Run the report: The report can be viewed in different formats such as HTML and PDF. It can be also sent by mail.
Troubleshooting:
exe tac report |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.