Hi folks,
We're using FGT-1500D cluster running FortiOS v5.2.6.
We have disabled memory logging and disk logging.
We upload logs in realtime to two FortiAnalyzer and we're wondering how things will go in case the two FAZ go down:
1/ Do we will lose new logs?
2/ Will the FortiGate store logs in a buffer waiting for one FAZ to come back alive?
3/ If yes to #2, does the FortiGate keep a trace of logs sent to one FAZ and the ones not the other FAZ?
4/ If yes to #2, what is the long retention capacity (buffer size)? Can it be adjustable?
In other words, is it possible to keep logging on FGT's disks when FAZ are unavailable and to send all the buffered logs, during FAZ downtime, to the FAZ when they become available while keeping logs consistency on both FAZ?
Thanks.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Yes, FGT can buffer some log to memory.
CLI:config sys fortianalyzer setting/set conn-timeout xx/
When fail to access FAZ and wait conn-timeout is reached , FGT will buffer log to memory, when the buffer is full, log will be droped.
The buffer size is not be adjustable, depend on your FGT memory size.
When connection to FAZ is recover, it will upload log in buffer to FAZ.Thanks.
Hi Jeff,
Thanks four inputs.
Just for information, likely the CLI command is in "config log fortianalyzer setting" (and not config sys fortianalyzer setting).
Still few questions please:
- Is it possible to buffer log to disk instead of into the memory?
- Do you know the memory buffer size for 1500D model?
- When the connection to one FAZ is recovered and is not with one other FAZ, does the FGT keep a consistence of log transferred to one FAZ and those which are not the other in the eventuality where one FAZ does not recover in the same time as the other one? Or potentially the amount of buffered logs will not be the same on the two FAZ?
Thanks again.
Hi
as of my information: - Is it possible to buffer log to disk instead of into the memory?
--> Clearly NO way
- Do you know the memory buffer size for 1500D model?
--> Memory Logging size whihch means 10 % of Memory
- When the connection to one FAZ is recovered and is not with one other FAZ, does the FGT keep a consistence of log transferred to one FAZ and those which are not the other in the eventuality where one FAZ does not recover in the same time as the other one? Or potentially the amount of buffered logs will not be the same on the two FAZ?
--> From my point of view same way meaning keeps in the buffer as soon as it comes available will be transfered.
hope this helps
have fun
Andrea
Is it possible to know how much of Fortigate's buffer size is actually utilised at any one time during loss of contact with FortiAnalyzer?
Is it possible to know how many log events were lost during loss of contact with FortiAnalyzer?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1710 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.