Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
polarpanda
New Contributor II

Best Practice to Save Logs Before Auto Delete

Hi FAZ Guru,

 

             I set our FAZ "alert and delete when usage reaches" to 85%, and I realize that FAZ tries to do the auto-delete log files everyday or every other day to keep total usage under 85%. For forensic or audit purpose, What's the best practice or your approach to save the old logs before it's deleted automatically?

              Any advice would be appreciated! Thanks!

2 REPLIES 2
Dongkwan
Staff
Staff

Hello,

 

The most common method is to use syslog in FAZ and forward it to a specific server. It can be managed by compress files on a linux server and delete files that have expired a certain period of time using crontab.

 

*. Send local logs to syslog server

https://docs.fortinet.com/document/fortianalyzer/7.4.0/administration-guide/414141/send-local-logs-t...

 

Thanks.

 

Regards,

Kwan
polarpanda
New Contributor II

Would it impact FAZ performance since it will constantly sending logs? how about use FTP to transfer rolled files?

Labels
Top Kudoed Authors