FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
akawade
Staff
Staff
Article Id 189827

Description


This article describes how to view log limits.

 

Scope

 

FortiAnalyzer.

Solution


The below command is use to view the Log Limit.

 

get system loglimit

 

Below is the sample output of the command get system loglimits:

 

GB/day : 250
Peak Log Rate : 10000
Sustained Log Rate : 4000

 

where:

 

GB/day : Number of Gigabytes used per day
Peak Log Rate : Peak Time log rate
Sustained Log Rate : Average Log Rate

 

These parameters can also be validated by GUI in the following path: Dashboard -> Status -> Insert Rate vs Received Rate.

 

Log limit_GUI.jpg

 

It is important to know this value due exceeding it could cause issues with the performance of the FortiAnalyzer, especially for on-premises devices. That happens due it is directly related to product capacity and the type of mode the FortiAnalyzer is being used (Analyzer or collector).

 

The capacity of some on-premises models could be checked here: FortiAnalyzer Data sheet

 

Log limit datasheet.jpg