Hi FAZ Guru,
I set our FAZ "alert and delete when usage reaches" to 85%, and I realize that FAZ tries to do the auto-delete log files everyday or every other day to keep total usage under 85%. For forensic or audit purpose, What's the best practice or your approach to save the old logs before it's deleted automatically?
Any advice would be appreciated! Thanks!
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello,
The most common method is to use syslog in FAZ and forward it to a specific server. It can be managed by compress files on a linux server and delete files that have expired a certain period of time using crontab.
*. Send local logs to syslog server
Thanks.
Regards,
Would it impact FAZ performance since it will constantly sending logs? how about use FTP to transfer rolled files?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1631 | |
1063 | |
749 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.