FortiManager
FortiManager supports network operations use cases for centralized management, best practices compliance, and workflow automation to provide better protection against breaches.
ckarwei
Staff
Staff
Article Id 204072
Description

This article explains the SD-WAN History Monitoring feature and provides guidance on how to enable it

Scope FortiManager.
Solution

By default, the SD-WAN monitoring feature is turned off, restricting the display of monitoring data to the last 10 minutes. To enable historical SD-WAN monitoring, an add-on license must be applied to the central management unit. This license extends monitoring capabilities, potentially resolves tunnel limitations, and improves overall system performance. 

 

To enable SD-WAN monitoring history feature use the following command:

 

FMG# config system admin setting

#(setting) set sdwan-monitor-history enable

#(setting) end

 ckarwei_0-1643764808131.png

 

Once the SD-WAN history monitor feature is enabled,  data can be filtered accordingly

ckarwei_1-1643764847692.png

 

Retention Period: Once enabled, the system retains SD-WAN monitoring history for up to 180 days by default. It is possible to view the data in various time frames, such as minutes, hours, days, or weeks.

 

To configure monitoring history storage:

 

FMG# config system admin setting

#(setting) set rtm-max-monitor-by-days <1-180>

#(setting) end

 

Resource Impact: The historical monitoring feature is optimized for live tunnel data; however, it may consume significant system resources depending on the number of devices managed

     

Data Processing Limitations: If FortiManager cannot process incoming data promptly due to the volume of connected FortiGate devices, unprocessed data older than two days will be dropped. This may result in gaps in the SD-WAN monitoring history.

 

SD-WAN history monitoring feature's impact:

Even with this enhancement, managing all live tunnels simultaneously may not be entirely seamless. While the SD-WAN historical monitoring feature is optimized for handling live tunnels, it can still place a significant load on system resources. To mitigate this, it is recommended to disable data-intensive monitoring features, such as SD-WAN historical monitoring, when system performance is a concern.

Comments
axel_gonzalez_FTNT

Hi, 

I don't see this command in our CLI reference docs


https://docs.fortinet.com/document/fortianalyzer/7.0.2/cli-reference/535041/admin#admin_setting

 

https://docs.fortinet.com/document/fortianalyzer/6.4.7/cli-reference/535041/admin#admin_setting

 

Do we need to enable something before sdwan-monitor-history is available?

ckarwei
Staff
Staff

Hi Axel,

 

This is for FortiManager CLI. FortiAnalyzer secure sd-wan monitor will follows the log retention policy.

axel_gonzalez_FTNT

I would suggest to edit step 2. 
Should be "FMG#" instead of "FAZ#"

Thanks!

ckarwei
Staff
Staff

Thanks for pointing that out! I have submitted the change.