I set our FAZ "alert and delete when usage reaches" to 85%, and I realize that FAZ tries to do the auto-delete log files everyday or every other day to keep total usage under 85%. For forensic or audit purpose, What's the best practice or your approach to save the old logs before it's deleted automatically?
The most common method is to use syslog in FAZ and forward it to a specific server. It can be managed by compress files on a linux server and delete files that have expired a certain period of time using crontab.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.