Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AlexFeren
New Contributor III

Clarification of Log Message Rate and Log Rate as shown by diagnose fortilogd

I understand 'Log Rate' to be SYSLOG messages received from devices, but what is a 'Log Message' as shown by 'diagnose fortilogd msgrate' command?

 

Also, is there a CLI command to show

[ul]
  • Insert Lag Time?
  • Insert Rate?[/ul]
  • 1 Solution
    scao_FTNT
    Staff
    Staff

    when FGT send log to FAZ, multiple logs may compress into 1 message for better performance, so you will see 2 rate, one is for message and one is for uncompressed log

     

    for log insert rate, pls try below

     

    diag deb en

    diag sql status sqlplugind PID: 428, now: 1444868152, uptime: 26308 Thread registered: 2 Log insert speed: logs/5sec: 115.0, logs/60sec: 215.7  Overall: 199.8 (5241880)

    ...

     

    there is no CLI for lag time since it might be different for different ADOM, different log table etc and I may still suggest you to monitor on GUI system settings lag time widget (or in log view check for each device historical log)

     

    Thanks

     

    Simon

    View solution in original post

    2 REPLIES 2
    scao_FTNT
    Staff
    Staff

    when FGT send log to FAZ, multiple logs may compress into 1 message for better performance, so you will see 2 rate, one is for message and one is for uncompressed log

     

    for log insert rate, pls try below

     

    diag deb en

    diag sql status sqlplugind PID: 428, now: 1444868152, uptime: 26308 Thread registered: 2 Log insert speed: logs/5sec: 115.0, logs/60sec: 215.7  Overall: 199.8 (5241880)

    ...

     

    there is no CLI for lag time since it might be different for different ADOM, different log table etc and I may still suggest you to monitor on GUI system settings lag time widget (or in log view check for each device historical log)

     

    Thanks

     

    Simon

    AlexFeren
    New Contributor III

    Thank you.

     

    > when FGT send log to FAZ, multiple logs may compress into 1 message for better performance, so you will see 2 rate, one is for message and one is for uncompressed log

     

    (If 'Log Messages' encapsulate variable number of Logs then) wouldn't it have been more useful to show finer-grained Log statistics instead of Log Message statistics (as 'diagnose fortilogd msgrate-type' and 'diagnose fortilogd msgrate-device' do)?

    Announcements

    Select Forum Responses to become Knowledge Articles!

    Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

    Labels
    Top Kudoed Authors