Hi all
how to do log retention in fortigate firewall. will the logs be stored in the firewall internal storage ?, If stored what is retention period for it.
also how to do log management in Fortigate ?
If FortiGate has a hard disk, it is enabled by default to store logs.
Disk logging is disabled by default if the FortiGate device only has flash memory because it is not recommended.
Constant rewrites to flash drives can reduce the lifetime and efficiency of the memory.
This metric is used to identify if logging into the system memory is enabled.
Enabling logging to the system memory is not recommended because this may affect the performance of the device. In addition, logs stored in the memory are cleared when the FortiGate device is restated.
Based on the network security best practice is recommended to store logs to a remote device.
Fortinet recommends uploading the logs for analysis to a remote device such as FortiAnalyzer or FortiGuard Analysis server.
By default, the maximum age for logs to store on disk is 7 days. Logs older than this are purged.
Please find below the link for the harddisk logging detail:-
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Hard-disk-utilization-by-the-FortiGate/ta-...
Regards
Priyanka
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.