Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ismailurek2
New Contributor III

FortiAnalyzer Retention Issue – Very Limited Analytics and Archive Logs Despite Long Uptime

Hello,

 

Our FortiAnalyzer has been running continuously for about 180 days, however:

- Analytics log is only 1 day,

- Archive log is kept for only 11 days.

- Disk occupancy is 85% (445 GB total available).

 

Our expectation was that these times would be much longer. No manual changes were made to the log retention settings.storage_info.png

I rebuilt FortiAnalyzer but then the day counts were updated as shown in the image below.storageinfo_after_rebuild.JPG

 

 

Best Regards,

İsmail Ürek

 

FortiAnalyzer 

5 REPLIES 5
AEK
SuperUser
SuperUser

Hi Ismail

I see you need much more disk space than 445GB.

AEK
AEK
ismailurek2
New Contributor III

Hi @AEK,

 

Would this affect the number of days my archive and analytics logs are retained? There is still available disk space, and I should still be able to view historical archive and analytics logs, right?

Will I be able to see more archive and analytics logs if I increase the disk?

 

Best Regards,

İsmail Ürek

AEK

Hi Ismail

What is the amount of daily analytic logs?

If I understand well from the screenshot, the disk space is almost consumed, so the oldest logs are cleaned up in order to make space for today's logs.

AEK
AEK
Jeremy5385
New Contributor III

I had a similar issue a while back where I was asking why only a few days of logs for ~1,500Gb of storage.  I ended up upping the CPU and memory quite a bit to fix the issue.  I think the internal SQL database was staved and couldn't complete processing the logs.  I would give this a try assuming you have the VM.

AEK

Than makes sense. Thanks for sharing, Jeremy.

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors