FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
kjiye
Staff & Editor
Staff & Editor
Article Id 261593
Description This article explains why FortiGate only retrieves 1-hour logs when trying to view FortiAnalyzer logs.
Scope FortiAnalyzer 7.0.4 or above.
Solution If the FortiAnalyzer has a lot of historical logs, the FortiGate GUI forward traffic log page can take a while to load unless there is a specific filter for the time range.
Regarding this, starting with FAZ 7.0.4, it has been changed to allow the checking of logs in increments of 1 hour only for logs for which no filter is specified.
When a request to check logs from FortiAnalyzer in FortiGate does not have a time-related condition, the scope for the Last 1 Hour is automatically added to the filter.
So, to check logs older than 1 hour, a time-related filter is required.