Dear Expertise,
I would like to ask you regarding backing our Fortigate log to tape is a good way or not? we are using FAZ and our license can support only 5GB per day.
Thanks
Solved! Go to Solution.
Hi
Then I think the 5GB/day limit has nothing to do with archiving or tape. I understand the issue here is not keeping logs for long time but is related to FAZ license for daily log capacity.
It is recommended to send all logs to FAZ (or SIEM) so the correlation is done properly. So in your case the recommendation is to extend the FAZ license.
If this is not an option for you and you only need to keep logs for traceability then you can forward the FGT logs to a free Linux based syslog server.
Hi Virek,
You can tune your logging in firewalls to optimise logging. And you can archive logs into any other severs for 90 days or as per your company policy.
Thanks
hi, we have tried to optimize log on firewall by using log filter even tho, that couldn't help
firewall keep send over 5GB log per day which is exit license limit
Hi Vireak
Usually companies archive logs on tape if a very long retention (several years) is needed.
For some companies this can be required for legal reasons.
On FortiAnalyzer you can download the files from menu "Log View > Logs > Log Browse" to send them to tape.
Ref: https://docs.fortinet.com/document/fortianalyzer/7.6.4/administration-guide/995169/downloading-a-log...
You can also use CLI command "execute backup logs ..." to send them to your archive server eventually in order to store them on tape.
Ref: https://community.fortinet.com/t5/FortiAnalyzer/Technical-Tip-Backup-and-restore-of-FortiAnalyzer-se...
Hi @AEK ,
so in case i require to backup log to Tape. Can i configure backup from fortigate to tape or from FAZ to tape?
FortiGate -> FAZ -> Tape server
FAZ -> Tape Server (by customize on backup fortigate log to tape server)
Am i correct with this workflow?
Do you really need this? Why Tape? Why not a modern SIEM or other product?
Hi, we have only FAZ and our Fortigate sending the log to FAZ more than 5GB per day, this is the reason why we are seeking idea whether it is a good idea to do it or not.
Hi
Then I think the 5GB/day limit has nothing to do with archiving or tape. I understand the issue here is not keeping logs for long time but is related to FAZ license for daily log capacity.
It is recommended to send all logs to FAZ (or SIEM) so the correlation is done properly. So in your case the recommendation is to extend the FAZ license.
If this is not an option for you and you only need to keep logs for traceability then you can forward the FGT logs to a free Linux based syslog server.
Hi AEK,
Thank you for your recommendation. I understand it now.
| User | Count |
|---|---|
| 2823 | |
| 1431 | |
| 812 | |
| 787 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.