Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
KPS
New Contributor III

FG200E - Memory-Log shows only 140-170 lines

Hi!

I am just using my first FG 200Es (OS: 5.4.4)

As they do not have a SSD, I need to log to memory. Everything is working fine, but the log is VERY small. It does just keep the last 140-170 lines.

 

Is this the "normal behaviour"?

 

Is it safe to increase the max-size of the memory-log:

config log memory global-setting
    set max-size 2236949
end

 

Standard-Size is 65536

 

One second thing: Is there any possibility to let the two nodes of a HA-cluster boot "one after the other", if I change that setting?

 

Thank you

Regards,

KPS

 

1 Solution
emnoc
Esteemed Contributor III

Did you cli execute log list for  the current sizes of the logs files? and the number of rolled logs ?

 

Ken

 

 

PCNSE 

NSE 

StrongSwan  

View solution in original post

PCNSE NSE StrongSwan
8 REPLIES 8
ede_pfau
SuperUser
SuperUser

Yes, the default size is quite small and won't hold much information. I usually increase it to 2 or 2.5 MB which can hold 1000s of lines.

As this is a 'must reboot' setting the cluster will reboot, sequentially, slave first. No choice.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
KPS
New Contributor III

Hi Ede!

 

Thank's for your answer!

2236949 byte seems to be the maximum size of the log on the 200Es. Is there any risk on chosing the maximum level? That looks quite small to me. The 200E has 4GB memory, so I do not understand that limit.

 

After changing that level, the cluster did _not_ reboot sequentially. Both nodes rebooted at the same time, and the VIPs have not been reachable for about 2 mins. Did your systems behave in another way?

 

Regards,

KPS (living near Heidelberg...)

emnoc
Esteemed Contributor III

Did you cli execute log list for  the current sizes of the logs files? and the number of rolled logs ?

 

Ken

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
KPS
New Contributor III

emnoc wrote:

Did you cli execute log list for  the current sizes of the logs files? and the number of rolled logs ?

Hi!

 

I will check this on monday, but I think, the log was full. Event log has shown 95% full some minutes after the start of the system.

 

KPS

emnoc
Esteemed Contributor III

Okay good

 

" A German and American talking over a beer is a festival " ;)

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
ede_pfau

In the past, the maximum size was indeed a percentage of the available RAM size, something like 10%. 2.1 MB is not a problem, you'll see. Of course, logging everything (esp. allowed traffic) will fill the logs quickly. That should be left for a debugging situation. Event log (beside security log) is far more important.

 

Sorry to hear that both cluster members rebooted at the same time. Another quirk to remember, as this shouldn't happen at all. I haven't experienced this before as I configure logging right at the beginning of a config, way before setting up the HA.

Funny that we live nearby; you can send me a PM if you like. You know, 2 Germans talking is just a meeting but 3 Germans talking is a Stammtisch :)

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
rwpatterson
Valued Contributor III

3 Americans talking is usually some form of counseling... ;)

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
KPS
New Contributor III

Hi Ede!

 

I was just confused that 2MB is the "maximum limit" on a system with 4GB memory because it should NEVER be a problem, or is it using any other "area", that is limited in any other way?

 

The first thing, I did was setting up HA, and now I am trying to adjust the systems.

 

Regards,

KPS

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors