FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
czamudio
Staff
Staff
Article Id 384785
Description

 

This article describes how to handle a specific problem with a slow FortiAnalyzer on a Virtual Machine environment.

 

Scope

 

FortiAnalyzer, general.

 

Solution

 

If FortiAnalyzer is slow, carry out a performance check to see if the VM is not installed on a heavy loaded hypervisor.

 

diagnose system klog

 

If the following is seen in the previous logs, consider the advice below:

 

<4>[104725.045794] hrtimer: interrupt took 7981185 ns

 

This indicates that the FortiAnalyzer VM is installed on a heavily loaded hypervisor, commonly on Hyper-V.

 

This applies to every virtual environment platform, however.

 

To fix this, try to move the FortiAnalyzer VM to another hypervisor. Remember that the FortiAnalyzer is a solution that requires high priority resources to operate correctly.

 

Related article:

Technical Tip: How to gather information and fix high CPU and memory utilization conditions