Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
polarpanda
New Contributor II

Best Practice to Save Logs Before Auto Delete

Hi FAZ Guru,

 

             I set our FAZ "alert and delete when usage reaches" to 85%, and I realize that FAZ tries to do the auto-delete log files everyday or every other day to keep total usage under 85%. For forensic or audit purpose, What's the best practice or your approach to save the old logs before it's deleted automatically?

              Any advice would be appreciated! Thanks!

2 REPLIES 2
Dongkwan
Staff
Staff

Hello,

 

The most common method is to use syslog in FAZ and forward it to a specific server. It can be managed by compress files on a linux server and delete files that have expired a certain period of time using crontab.

 

*. Send local logs to syslog server

https://docs.fortinet.com/document/fortianalyzer/7.4.0/administration-guide/414141/send-local-logs-t...

 

Thanks.

 

Regards,

Kwan
polarpanda
New Contributor II

Would it impact FAZ performance since it will constantly sending logs? how about use FTP to transfer rolled files?

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors