FortiWeb
A FortiWeb can be configured to join a Security Fabric through the root or downstream FortiGate.
ddsouza_FTNT
Staff
Staff
Article Id 204654
Description This article describes steps to collect the logs needed for investigating the high log disk usage and log-related problems.
Scope For version 6.0 and above.
Solution

For Logdisk usage: Log in to FortiWeb SSH by using the default 'admin' account and collect the output of the following commands (make sure to record the SSH session output to a file).

 

Fortiweb# get sys status
Fortiweb# get log disk
Fortiweb# get log traffic-log
Fortiweb# diagnose system mount list

Fortiweb# diagnose debug crashlog show
Fortiweb# diagnose hardware harddisk list
Fortiweb# diagnose hardware logdisk info
Fortiweb# fn ps
Fortiweb# fn ls -lh /var/log
Fortiweb# fn ls -lh /var/log/fwlog/root/disklog/
Fortiweb# fn ls -lh /var/log/fwlog/root/database/
Fortiweb# fn du -sch /var/log/
Fortiweb# fn du -h /var/log/
Fortiweb# fn du -sch /var/log/fwlog
Fortiweb# fn du -h /var/log/fwlog
Fortiweb# fn du -sch /var/log/fwlog/root/disklog/
Fortiweb# fn du -h /var/log/fwlog/root/disklog/
Fortiweb# fn du -sch /var/log/fwlog/root/database/
Fortiweb# fn du -h /var/log/fwlog/root/database/
Fortiweb# fn du -sch /var/log/fwlog/root
Fortiweb# fn du -h /var/log/fwlog/root

 

For Traffic/attack/event logs related problems: Log in to FortiWeb SSH and run the following debug commands. (Make sure to record the SSH session output to a file.)

 

Fortiweb# diagnose deb reset
Fortiweb# diagnose debug application logd 7
Fortiweb# diagnose debug enable

 

Reproduce the problem and wait for two minutes.

 

And then, turn off debugging by running the following commands.

 

Fortiweb# diagnose debug disable

 

Log in to FortiWeb SSH using the default 'admin' and run the following debug commands. (make sure to record the SSH session output to a file).

 

   Fortiweb# fn cat /var/log/dlog_indexd

   Fortiweb# fn cat /var/log/dlog_logd

   Fortiweb# fn cat /var/log/mysql/error.log

   

   Fortiweb# fn cat /proc/miglog/alog/brief

   Fortiweb# fn cat /proc/miglog/tlog/brief

   Fortiweb# fn cat /proc/miglog/elog/brief

 

Wait for 2 minutes and execute following commands.

 

   Fortiweb# fn cat /proc/miglog/alog/brief

   Fortiweb# fn cat /proc/miglog/tlog/brief

   Fortiweb# fn cat /proc/miglog/elog/brief

 

As the logs not showing up problem could be the byproduct of high logdisk usage problem, collect the output of the commands mentioned above in the 'For Logdisk usage'.

 

  • Along with the above files, attach the configuration backup and the system debug file.

To download the system debug file, go to System -> Maintenance -> Debug -> Debug Log and Download the debug log file (refer to the screenshot added below).

 

ddsouza_FTNT_0-1644561803597.png

 

  • Attach all the files to the ticket.

Related article:
Technical Tip: How to identify and troubleshoot a hard disk/log disk failure with FortiWeb