Hello,
To meet our conformity requirements, our organization sends all FortiGate logs to a syslog server. However, approximately 90% of these logs have limited usefulness for security monitoring purposes. If we were to remove these logs from FortiGate/FortiAnalyzer, we would free up significant storage space for the valuable logs, resulting in improved traceability over time.
We are wondering if it is possible to implement distinct policies for log storage. Specifically, we would like to delete certain logs shortly after they have been forwarded to the syslog server.
Thank you
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Yes, it is possible to automate the removal of certain logs on Fortinet using scripts or automation tools. Fortinet provides APIs and CLI commands that can be used to automate various tasks, including log management.
For example, you can use the Fortinet FortiManager or FortiAnalyzer tools to automate log retention policies and purging of logs. You can also use scripting languages such as Python, PowerShell, or Bash to create custom scripts that can automate log removal based on specific criteria such as age, size, or severity.
Hello Johnharper,
Thanks for your answer. I am looking for log management in the reference manual, but i can't find it.
Do you think you could help me find the details in the reference manual?
Thank you
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.