Hey guys. I've been having a problem with logs disappearing since I updated firmware version 7.0.2 to 7.6.2 for a period longer than a week. When a week of log collection "Incidents & Events > Event Monitor" is completed, the date of the first occurrence returns to 3 days ago, and we have much more logs stored than 3 days ago. I already ran the command to rewrite the sql, I got the logs from February 28, 2025 to March 7, 2025 (exactly one week). I would like to know if there is any way to completely restore from the beginning (I believe it is around May 2022) all the logs, including those from the Event Monitor session and for the logs to remain permanent. Below are some images of the problem.
This is the collection after I ran the sql library rewrite command which lasted for 9 days, as in the image below.
Today (March 7, 2025), the problem with showing the logs appeared again and you can only see the events from 3 days ago as in the image
Hello,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hello,
We are still looking for someone to help you.
We will come back to you ASAP.
Thanks,
To troubleshoot missing event monitor logs after one week on FortiAnalyzer:
This is my current configuration, looks right?
The commands results, is there something wrong?
"Device Log Settings: Check the device log settings under the "Advanced" tab. Ensure the "Automatically Delete" section is configured correctly, with the "Device log store duration" set to a value that meets your retention needs".
This is my current configuration, looks right?
@Anthony_E After performing a check on my fortigate, I found that there are much more logs archived than stored. Would there be any way to restore these stored logs to storage?
Hi,
the event monitor list is a separated table of the database, you can see a limited size of logs
you can try to extend with
config sys log alert
set max-alert-count 50000 < -- it depends on the version, it may be 100000
end
After upgrading FortiAnalyzer from 7.0.2 to 7.6.2 the SQL event database was partially rebuilt which is why Event Monitor only shows about a week of logs and the “First Occurrence” resets to 3 days ago. The raw logs may still exist on disk but are not fully indexed in SQL. You can confirm this from Log View and by checking System Settings > Storage Info for disk quota. To restore visibility, run a full SQL database rebuild (execute sql-local rebuild-db). If older logs were purged due to quota limits, only restoring from backup will bring them back. In case of SQL corruption, a repair tool like Stellar Repair for MySQL can help recover missing or inaccessible log data.
User | Count |
---|---|
2549 | |
1356 | |
795 | |
646 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.