Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ryeh028
New Contributor

FortiAnalyzer 7 analytic data

We recently conducted an internal penetration test and the testing machine generated 20 times more messages on our analyzer.  I have already deleted log files, however, is there a way to delete the messages generated by that PEN test machine from the analytic database?  Thanks!

1 Solution
Debbie_FTNT
Staff
Staff

Hey ryeh028,

there is no way to delete entries from the analytic database directly.

The only way to remove those log messages is to first delete them from archive logs, and then rebuild the database:

-> this will discard the current database with the logs in question

-> the new database will be rebuilt based on archive logs (where the logs in question were already removed)

-> the new database should not contain the logs in question

KB on rebuilding a database: https://community.fortinet.com/t5/FortiAnalyzer/Technical-Tip-FortiAnalyzer-SQL-database-delete-and-...

+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++

View solution in original post

2 REPLIES 2
Debbie_FTNT
Staff
Staff

Hey ryeh028,

there is no way to delete entries from the analytic database directly.

The only way to remove those log messages is to first delete them from archive logs, and then rebuild the database:

-> this will discard the current database with the logs in question

-> the new database will be rebuilt based on archive logs (where the logs in question were already removed)

-> the new database should not contain the logs in question

KB on rebuilding a database: https://community.fortinet.com/t5/FortiAnalyzer/Technical-Tip-FortiAnalyzer-SQL-database-delete-and-...

+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++
ryeh028

Thank you!

 

Randy

Labels
Top Kudoed Authors