FortiSIEM Discussions
adem_netsys
Contributor II

About closed collector

Hi guys,

 

We interrupted the log flow of a collector that we collected logs and closed it. We would like to see the logs here backward. When we search, we get a response after a long time (about 20 minutes) even if we do it for 10 minutes, and some fields are empty, even though Fortinet has its own products. Does anyone have any idea why?

 

Thank you

 

 

2 REPLIES 2
aebadi
Staff
Staff

Hi,
How long was the collector offline? It’s possible the logs rolled over or were lost during that time.

You can check available log files and timestamps with:
ls -la /opt/phoenix/log/ | grep phoenix

This might explain the delay and missing data.

adem_netsys

Hi @aebadi 

Collector has just been closed, there is no new log flow, we want to see the previous logs. Logs are coming, but short-term search times also take a long time. Why do you think logs can be lost here?