I registered more than 25 devices in my Fortianalyzer without problems, but I am not able to keep two of them 100% connected. I can see the logs and they have registered correctly in the analyzer and I can see the logs in real time, but if I do a filter for a longer period of time, it does not show data. Both the equipment and the Fortyanalyzer are in the latest version, both have policies allowing communication to be released for everything, like the others that worked. Can anyone help me with the demand?
Hello @VANESSON_SANTOS,
Could you let us know how long you are able to see the logs and what filter you are applying?
Hello @VANESSON_SANTOS
Check the status of the problematic devices: Ensure they show as Online
From the FortiGate CLI of the affected devices, check the status of log transmission:
execute log fortianalyzer test-connectivity
In the FortiAnalyzer GUI: Go to System Settings > Disk Settings > Device Log Settings.
Check if there are quotas assigned to the problematic devices. If the quota is too small or exhausted, historical logs may not be stored
Thanks
Pavan
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1110 | |
759 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.