FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
KenYap
Staff
Staff
Article Id 251098
Description This article describes how to check FortiAnalyzer archive logs.
Scope FortiAnalyzer.
Solution

To check the archive logs rollover settings at the current ADOM:

 

1) Select the ADOM to check.

2) Select System Settings.

3) Select 'Advanced', then select 'Device Logs Settings'.

4) Under Registered Device Logs:

    Roll log file when size exceeds: 200MB 

     Roll log files at scheduled time: Weekly Sunday 12am

 

*The logs size received at FortiAnalyzer will increase until it exceeds 200MB, then the logs will roll over/ archived it. 

*If the Roll logfiles is enabled at the scheduled time, the logs will roll over it at that specific time that is configured.

.

Refer to below image:


FAZ Archive Logs Roll Over Settings.PNG

 

Below is an example of logs rolling over once it exceeds 200MB.

In this example, notice that tlog.1680482237.log is changed to tlog.1680482237.log.gz.

The size of .log is bigger than .log.gz, because the .log.gz is roll over/ archived.

 

Refer to below image:

FAZ Archive Logs Roll Over.PNG

 

FortiAnalyzer documentation:

https://docs.fortinet.com/product/fortianalyzer/7.2


To contact support by phone:
http://www.fortinet.com/support/contact_support

Contributors