We want to understand how FortiSIEM handles log collection from agents and syslog sources during network outages. In particular, we are looking for technical guidance on the following points:
How agents and syslog sources manage logs during network outages in FortiSIEM
For example; we request a guiding evaluation with technical explanations especially on the following issues:
How long the agents can keep the logs in the buffer when the network connection is lost, the maximum size definition that the local disk can be used at this point,
What kind of log losses can be experienced in case of buffer overflow,
Can you help with issues such as the process of forwarding delayed logs in case of reconnection?
For the collector, check this article that explains how you can increase the maximum size of the buffer. Obviously, the longer the outage, the larger the buffer, if you want to run some estimations, you can check your EPS on the collector, then consider each event size as 1000KB and do the math.
For the windows agent, you can change the regestry settings under "HKEY_LOCAL_MACHINE\Software\Fortinet\FortiSIEM", I think it's called "MaxDBSizeInMB"
Welcome to your new Fortinet Community!
You'll find your previous forum posts under "Forums"
User | Count |
---|---|
72 | |
25 | |
15 | |
10 | |
10 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.