Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Asyraf
New Contributor II

FortiAnalyzer CPU Usage High

Hi,

 

I checking on my FortiAnalyzer, seem the resource for the CPU really high. I monitored it almost 1 day and restart some of the service but still same. Based on the exe top output, some application that utilized most of the cpu are siemagentd & postgress. Its take a lot of time to generate a report when the cpu high.

 

Anyone can assist me on this ?

 

 

1 Solution
fricci_FTNT
Staff
Staff

Hi @Asyraf ,


You may have gone already through the initial troubleshooting process explained in the article below:
https://community.fortinet.com/t5/FortiAnalyzer/Technical-Tip-How-to-gather-information-and-fix-high...

If yes, please raise a ticket with our support so a FortiAnalyzer TAC engineer can be assigned to investigate the issue further.

 

Best regards,

---
If you have found a useful article or a solution, please like and accept it to make it easily accessible to others.

View solution in original post

4 REPLIES 4
fricci_FTNT
Staff
Staff

Hi @Asyraf ,


You may have gone already through the initial troubleshooting process explained in the article below:
https://community.fortinet.com/t5/FortiAnalyzer/Technical-Tip-How-to-gather-information-and-fix-high...

If yes, please raise a ticket with our support so a FortiAnalyzer TAC engineer can be assigned to investigate the issue further.

 

Best regards,

---
If you have found a useful article or a solution, please like and accept it to make it easily accessible to others.
Asyraf
New Contributor II

Yes, already go to the article & restart some of the service but it still same.

Will proceed with TAC.

 

TQ

smkml
Staff
Staff

Hi @Asyraf ,

 

Based on the process you mentioned it is related to siem module in the FAZ caused it used up CPU resources, and you may want to disable it follow by KB below:

https://community.fortinet.com/t5/FortiAnalyzer/Technical-Tip-How-to-improve-FortiAnalyzer-performan...

Asyraf
New Contributor II

TQ for the KB, based on the license we dont have the SOAR & SIEM bundle service. So we just can disable this features cause as per checked it is running, but it required downtime so will do it during the maintenance time. Also i noticed the CPU was high during our office hours, does it mean that our current FAZ 400E cant cater our current traffic ?

Our average Log around 3200.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors