FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
cdemar
Staff
Staff
Article Id 197432
Description
This article describes the information provided by the 'Total Logs for Analytic'" in the FortiAnalyzer LogView GUI.
Solution
The Fortianalyzer provides the 'Total Logs for Analytics" information in the bottom left of the FAZ LogView screen as below:

logview1.png

This indicator shows that the oldest log in the FortiAnalyzer analytics DB has been logged 36 days and 21 hours ago. 
This oldest log in the DB can be located in any category (Traffic, Anti virus, Intrustion Prevention, etc  ). 
Depending on the retention policy configured and the daily volume of logs received, it happens that the oldest traffic log does not correspond to the oldest log in the DB.
To find out the oldest traffic log available in the analytics, you can change the sorting order in the traffic log category, as shown below:
logview2.png


 

Contributors