Hi Community Member,
I have a requirement of 150 days data retention policy. 30 days should be online and 120 day on archive. I am getting little bit confuse in FortiSIEM documentation.
There are two types of retention policy (archival retention policy and online retention policy), we have configured data storage (online and archive) on NFS server.
If I set data retention to 30 days in online retention policy, what will fortiSIEM will do after 30 days ? will it move data to archive or it will delete the data ?
Thanks in advance.
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
With this event database setup eventDB as online and eventDB as archive, once the online retention policy time had been bet, then the event is moved to the archive at the end of the day.
With this event database setup eventDB as online and eventDB as archive, once the online retention policy time had been bet, then the event is moved to the archive at the end of the day.
Welcome to your new Fortinet Community!
You'll find your previous forum posts under "Forums"
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.