Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
gwaihir
New Contributor III

Indexing archive logs for Analytics how to do it? FAZ 7.2.4

Hello.

 

I'm trying to indexing logs from log_browse (archive) to do some analytics, but what are the steps to perform this?

 

Thank you!

4 REPLIES 4
srajeswaran
Staff
Staff

This article explains the procedure - https://community.fortinet.com/t5/Internal-Knowledge-Base-Articles/Technical-Note-How-to-index-logs-...

 

Regards,
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
gwaihir
New Contributor III

It show denied access, I guess, this is "internal-knowledge-base"

 

@srajeswaran there is an update with access denied message.Log_Error_MSG.PNG

srajeswaran

Hi @gwaihir , my apologies, didnt realize it was internal only. Below given is the external one.

https://community.fortinet.com/t5/FortiAnalyzer/Technical-Tip-FortiAnalyzer-SQL-database-delete-and-...

Be aware that rebuilding the database is resource and time consuming and the reports as well log view and FortiView will not be fully usable until the rebuild is over.

Regards,
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
jasonhong
Staff
Staff

In order to index raw logs into analytics logs, you merely have to run a SQL database rebuild via below command.

# exec sql-local rebuild-db


Below doc guide explains further on archive and analytics logs.

https://docs.fortinet.com/document/fortianalyzer/7.2.4/administration-guide/761825/analytics-and-arc...

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors