FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
WinterSnowYap
Article Id 378935
Description This article describes how to troubleshoot and remove Deleted ADOM information at log volume ADOMs.
Scope FortiAnalyzer.
Solution
  1. A new ADOM called 'ADOM_TestA' has been created.

 

FAZ ADOM information_01.PNG

 

  1. Run CLI commands to check the log volume for all ADOMs:

 

diagnose fortilogd logvol-adom all

 

FAZ ADOM information_02.PNG

 

 

  1. Remove the 'ADOM_TestA' ADOM.

 

FAZ ADOM information_03.PNG

 

  1. Run CLI command to check the log volume for all ADOMs:

 

diagnose fortilogd logvol-adom all

 

  1. The FortiAnalyzer shows 'ADOM_TestA' ADOM information:

 

FAZ ADOM information_04.PNG

 

  1. To remove 'ADOM_TestA' ADOM from the log volume information for all ADOMs, perform a FortiAnalyzer reboot which is either using GUI or CLI command.  

 

FAZ ADOM information_05.PNG

 

  1. After FortiAnalyzer is rebooted, run the CLI command to check the log volume for all ADOMs:

 

diagnose fortilogd logvol-adom all

 

  1. This time, FortiAnalyzer does not show 'ADOM_TestA' ADOM information.

 

FAZ ADOM information_06.PNG