This article describes how to identify the reason for deletion or loss of Analytics or Archive logs in FortiAnalyzer.
FortiAnalyzer.
Due to Log retention settings, FortiAnalyzer can delete Analytic and Archive logs for an ADOM. Sometimes admin can also delete log files manually. Following information about event logs can help identify the cause of log deletion.
Event log for deletion of device logs from the Database:
Event log for deletion of Archived log files:
Event logs for manually deleting the log file:
Note:
Ensure the Data Policy and Disk Allocation are configured efficiently. To adjust the Data Policy and Disk Allocation, navigate to System Settings -> ADOM -> Edit ADOM.
Related documents:
Analytic and Archived Log retention periods
Fortianalyzer event logs
Technical Tip: Archive vs Analytic Logs
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.